From 2a6277c0c3bfab781799cd685ae99396011eca1d Mon Sep 17 00:00:00 2001 From: William Wernert Date: Fri, 30 Jul 2021 15:46:39 -0400 Subject: [PATCH] Fix field names in logscan pipeline --- salt/elasticsearch/files/ingest/logscan.alert | 14 ++++++++------ 1 file changed, 8 insertions(+), 6 deletions(-) diff --git a/salt/elasticsearch/files/ingest/logscan.alert b/salt/elasticsearch/files/ingest/logscan.alert index 3a3debabc..88772c16c 100644 --- a/salt/elasticsearch/files/ingest/logscan.alert +++ b/salt/elasticsearch/files/ingest/logscan.alert @@ -11,12 +11,14 @@ { "remove": { "field": "start_time", "ignore_missing": true } }, { "remove": { "field": "end_time", "ignore_missing": true } }, { "rename": { "field": "source_ip", "target_field": "source.ip", "ignore_missing": true } }, - { "append": { "field": "logsscan.source.ips", "value": "{{{source.ip}}}", "ignore_failure": true } }, - { "rename": { "field": "source_ips", "target_field": "logscan.source.ips", "ignore_missing": true } }, - { "set": { "if": "ctx.model == 'kff'", "field": "rule.name", "value": "LOGSCAN KFF MODEL THRESHOLD" } }, - { "set": { "if": "ctx.model == 'kff'", "field": "rule.description", "value": "High ratio of login failures in 5 minute window" } }, - { "set": { "if": "ctx.model == 'kl'", "field": "rule.name", "value": "LOGSCAN KL MODEL THRESHOLD" } }, - { "set": { "if": "ctx.model == 'kl'", "field": "rule.description", "value": "Large number of login failures in 1 hour window" } }, + { "append": { "field": "logscan.source.ips", "value": "{{{source.ip}}}", "ignore_failure": true } }, + { "rename": { "field": "top_source_ips", "target_field": "logscan.source.ips", "ignore_missing": true } }, + { "set": { "if": "ctx.model == 'k1'", "field": "rule.name", "value": "LOGSCAN K1 MODEL THRESHOLD" } }, + { "set": { "if": "ctx.model == 'k1'", "field": "rule.description", "value": "High number of logins from single IP in 1 minute window" } }, + { "set": { "if": "ctx.model == 'k5'", "field": "rule.name", "value": "LOGSCAN K5 MODEL THRESHOLD" } }, + { "set": { "if": "ctx.model == 'k5'", "field": "rule.description", "value": "High ratio of login failures from single IP in 5 minute window" } }, + { "set": { "if": "ctx.model == 'k60'", "field": "rule.name", "value": "LOGSCAN K60 MODEL THRESHOLD" } }, + { "set": { "if": "ctx.model == 'k60'", "field": "rule.description", "value": "Large number of login failures in 1 hour window" } }, { "rename": { "field": "model", "target_field": "logscan.model" } }, { "rename": { "field": "num_attempts", "target_field": "logscan.attempts.total.amount", "ignore_missing": true } }, { "rename": { "field": "num_failed", "target_field": "logscan.attempts.failed.amount", "ignore_missing": true } },