Logstash Module - Change it to arrays

This commit is contained in:
Mike Reeves
2018-10-16 16:46:04 -04:00
parent 57039d83c8
commit 2f517a6c8d

View File

@@ -11,18 +11,21 @@ input {
filter { filter {
if "ids" in [tags] { if "ids" in [tags] {
mutate { mutate {
add_field => {"sensor_name" => "%{beat.name}"} add_field => {"sensor_name" => "%{[beat][name]}"}
add_field => {"syslog-host_from" => "%{beat.hostname}"} add_field => {"syslog-host_from" => "%{[beat][hostname]}"}
remove_tag => ["beat"] remove_tag => ["beat"]
rename => { "host" => "beat_host" } rename => { "host" => "beat_host" }
remove_field => ["beat.name", "beat.hostname"] remove_field => ["[beat][name]", "[beat][hostname]"]
} }
} }
if "bro" in [tags] { if "bro" in [tags] {
mutate { mutate {
add_field => {"sensor_name" => "%{[beat][name]}"}
add_field => {"syslog-host_from" => "%{[beat][hostname]}"}
remove_tag => ["beat"] remove_tag => ["beat"]
rename => { "host" => "beat_host" } rename => { "host" => "beat_host" }
remove_field => ["[beat][name]", "[beat][hostname]"]
} }
} }
} }