Logstash Module - Change it to arrays

This commit is contained in:
Mike Reeves
2018-10-16 16:46:04 -04:00
parent 57039d83c8
commit 2f517a6c8d

View File

@@ -11,18 +11,21 @@ input {
filter {
if "ids" in [tags] {
mutate {
add_field => {"sensor_name" => "%{beat.name}"}
add_field => {"syslog-host_from" => "%{beat.hostname}"}
add_field => {"sensor_name" => "%{[beat][name]}"}
add_field => {"syslog-host_from" => "%{[beat][hostname]}"}
remove_tag => ["beat"]
rename => { "host" => "beat_host" }
remove_field => ["beat.name", "beat.hostname"]
remove_field => ["[beat][name]", "[beat][hostname]"]
}
}
if "bro" in [tags] {
mutate {
add_field => {"sensor_name" => "%{[beat][name]}"}
add_field => {"syslog-host_from" => "%{[beat][hostname]}"}
remove_tag => ["beat"]
rename => { "host" => "beat_host" }
remove_field => ["[beat][name]", "[beat][hostname]"]
}
}
}