mirror of
https://github.com/Security-Onion-Solutions/securityonion.git
synced 2025-12-06 09:12:45 +01:00
Logstash - Wazuh parsing updates
This commit is contained in:
@@ -15,6 +15,7 @@ filter {
|
|||||||
remove_tag => ["beat"]
|
remove_tag => ["beat"]
|
||||||
add_field => { "sensor_name" => "%{[beat][name]}" }
|
add_field => { "sensor_name" => "%{[beat][name]}" }
|
||||||
add_field => { "syslog-host_from" => "%{[beat][name]}" }
|
add_field => { "syslog-host_from" => "%{[beat][name]}" }
|
||||||
|
remove_field => [ "beat", "prospector", "input", "offset" ]
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
if [type] =~ "ossec" {
|
if [type] =~ "ossec" {
|
||||||
@@ -22,6 +23,7 @@ filter {
|
|||||||
rename => { "host" => "beat_host" }
|
rename => { "host" => "beat_host" }
|
||||||
remove_tag => ["beat"]
|
remove_tag => ["beat"]
|
||||||
add_field => { "syslog-host_from" => "%{[beat][name]}" }
|
add_field => { "syslog-host_from" => "%{[beat][name]}" }
|
||||||
|
remove_field => [ "beat", "prospector", "input", "offset" ]
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
Reference in New Issue
Block a user