Update Zeek and Strelka

This commit is contained in:
Wes Lambert
2020-04-01 19:09:38 +00:00
parent 82c99edbfc
commit 1df2302287
2 changed files with 5 additions and 5 deletions

View File

@@ -10,17 +10,16 @@
filter { filter {
if "zeek" in [tags] and "test_data" not in [tags] and "import" not in [tags] { if [module] =~ "zeek" {
mutate { mutate {
##add_tag => [ "conf_file_9000"] ##add_tag => [ "conf_file_9000"]
} }
} }
} }
output { output {
if "zeek" in [tags] and "test_data" not in [tags] and "import" not in [tags] { if [module] =~ "zeek" {
# stdout { codec => rubydebug }
elasticsearch { elasticsearch {
pipeline => "%{event_type}" pipeline => "%{module}.%{dataset}"
hosts => "{{ ES }}" hosts => "{{ ES }}"
index => "so-zeek-%{+YYYY.MM.dd}" index => "so-zeek-%{+YYYY.MM.dd}"
template_name => "so-zeek" template_name => "so-zeek"

View File

@@ -10,7 +10,7 @@
filter { filter {
if [event_type] =~ "strelka" { if [module] =~ "strelka" {
mutate { mutate {
##add_tag => [ "conf_file_9000"] ##add_tag => [ "conf_file_9000"]
} }
@@ -19,6 +19,7 @@ filter {
output { output {
if [event_type] =~ "strelka" { if [event_type] =~ "strelka" {
elasticsearch { elasticsearch {
pipeline => "%{module}.%{dataset}"
hosts => "{{ ES }}" hosts => "{{ ES }}"
index => "so-strelka-%{+YYYY.MM.dd}" index => "so-strelka-%{+YYYY.MM.dd}"
template_name => "so-common" template_name => "so-common"