From 115e0a6fee52cf9a789209d0668b97050f2e72bf Mon Sep 17 00:00:00 2001 From: William Wernert Date: Tue, 13 Jul 2021 12:04:10 -0400 Subject: [PATCH] [fix] Add missing comma --- salt/elasticsearch/files/ingest/logscan | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/salt/elasticsearch/files/ingest/logscan b/salt/elasticsearch/files/ingest/logscan index 6cd32dcbc..d199161a5 100644 --- a/salt/elasticsearch/files/ingest/logscan +++ b/salt/elasticsearch/files/ingest/logscan @@ -14,7 +14,7 @@ { "set": { "if": "ctx.model == kff", "field": "rule.description", "value": "High ratio of login failures in 5 minute window" } }, { "set": { "if": "ctx.model == kl", "field": "rule.name", "value": "LOGSCAN KL MODEL THRESHOLD" } }, { "set": { "if": "ctx.model == kl", "field": "rule.description", "value": "Large number of login failures in 1 hour window" } }, - { "rename": { "field": "model", "target_field": "logscan.model" } } + { "rename": { "field": "model", "target_field": "logscan.model" } }, { "rename": { "field": "num_attempts", "target_field": "logscan.attempts.total.amount", "ignore_missing": true } }, { "rename": { "field": "num_failed", "target_field": "logscan.attempts.failed.amount", "ignore_missing": true } }, { "script": { "lang": "painless", "source": "ctx.logscan.attempts.succeeded.amount = ctx.logscan.attempts.total.amount - ctx.logscan.attempts.failed.amount" , "ignore_failure": true} },