From 24c325e9a10f2a9f1d83bbe4cf16d3266e58273c Mon Sep 17 00:00:00 2001 From: Doug Burks Date: Thu, 10 Sep 2020 06:41:19 -0400 Subject: [PATCH] Fix Elasticsearch parsing for Zeek Intel Indicator #1309 --- salt/elasticsearch/files/ingest/zeek.intel | 1 + 1 file changed, 1 insertion(+) diff --git a/salt/elasticsearch/files/ingest/zeek.intel b/salt/elasticsearch/files/ingest/zeek.intel index 1f6e7829e..8be25c9ef 100644 --- a/salt/elasticsearch/files/ingest/zeek.intel +++ b/salt/elasticsearch/files/ingest/zeek.intel @@ -3,6 +3,7 @@ "processors" : [ { "remove": { "field": ["host"], "ignore_failure": true } }, { "json": { "field": "message", "target_field": "message2", "ignore_failure": true } }, + { "dot_expander": { "field": "seen.indicator", "path": "message2", "ignore_failure": true } }, { "rename": { "field": "message2.seen.indicator", "target_field": "intel.indicator", "ignore_missing": true } }, { "dot_expander": { "field": "seen.indicator_type", "path": "message2", "ignore_failure": true } }, { "rename": { "field": "message2.seen.indicator_type", "target_field": "intel.indicator_type", "ignore_missing": true } },