Logstash - Wazuh parsing updates

This commit is contained in:
Wes Lambert
2018-12-14 18:00:19 +00:00
parent 46372d1384
commit 172c9e0593

View File

@@ -15,6 +15,7 @@ filter {
remove_tag => ["beat"] remove_tag => ["beat"]
add_field => { "sensor_name" => "%{[beat][name]}" } add_field => { "sensor_name" => "%{[beat][name]}" }
add_field => { "syslog-host_from" => "%{[beat][name]}" } add_field => { "syslog-host_from" => "%{[beat][name]}" }
remove_field => [ "beat", "prospector", "input", "offset" ]
} }
} }
if [type] =~ "ossec" { if [type] =~ "ossec" {
@@ -22,6 +23,7 @@ filter {
rename => { "host" => "beat_host" } rename => { "host" => "beat_host" }
remove_tag => ["beat"] remove_tag => ["beat"]
add_field => { "syslog-host_from" => "%{[beat][name]}" } add_field => { "syslog-host_from" => "%{[beat][name]}" }
remove_field => [ "beat", "prospector", "input", "offset" ]
} }
} }
} }