mirror of
https://github.com/Security-Onion-Solutions/securityonion.git
synced 2026-01-30 11:54:13 +01:00
Filebeat - Modify config for IDS type
This commit is contained in:
@@ -30,9 +30,9 @@ filebeat.prospectors:
|
||||
paths:
|
||||
- /suricata/eve.json
|
||||
fields:
|
||||
type: snort
|
||||
type: ids
|
||||
engine: suricata
|
||||
fields_under_root: true
|
||||
tags: ["ids"]
|
||||
clean_removed: false
|
||||
close_removed: false
|
||||
|
||||
|
||||
Reference in New Issue
Block a user