From 26efad1c45898d2b40c91f0b9e42816fb72ed74c Mon Sep 17 00:00:00 2001 From: weslambert Date: Wed, 1 Apr 2020 11:30:02 -0400 Subject: [PATCH 1/2] Update Strelka log path --- salt/filebeat/init.sls | 1 + 1 file changed, 1 insertion(+) diff --git a/salt/filebeat/init.sls b/salt/filebeat/init.sls index 38fd72b32..12b429e51 100644 --- a/salt/filebeat/init.sls +++ b/salt/filebeat/init.sls @@ -56,6 +56,7 @@ so-filebeat: - /opt/so/log/filebeat:/usr/share/filebeat/logs:rw - /opt/so/conf/filebeat/etc/filebeat.yml:/usr/share/filebeat/filebeat.yml:ro - /nsm/zeek:/nsm/zeek:ro + - /nsm/strelka/log:/nsm/strelka/log:ro - /opt/so/log/suricata:/suricata:ro - /opt/so/wazuh/logs/alerts:/wazuh/alerts:ro - /opt/so/wazuh/logs/archives:/wazuh/archives:ro From f13093dc51960d899e14ed380ef6fc9f08b0708c Mon Sep 17 00:00:00 2001 From: weslambert Date: Wed, 1 Apr 2020 11:31:57 -0400 Subject: [PATCH 2/2] Add message rename --- salt/elasticsearch/files/ingest/zeek.weird | 1 + 1 file changed, 1 insertion(+) diff --git a/salt/elasticsearch/files/ingest/zeek.weird b/salt/elasticsearch/files/ingest/zeek.weird index 7c138f991..2665bbb33 100644 --- a/salt/elasticsearch/files/ingest/zeek.weird +++ b/salt/elasticsearch/files/ingest/zeek.weird @@ -2,6 +2,7 @@ "description" : "zeek.weird", "processors" : [ { "remove": { "field": ["host"], "ignore_failure": true } }, + { "json": { "field": "message", "target_field": "message2", "ignore_failure": true } }, { "rename": { "field": "message2.name", "target_field": "weird.name", "ignore_missing": true } }, { "rename": { "field": "message2.addl", "target_field": "weird.additional_info", "ignore_missing": true } }, { "rename": { "field": "message2.notice", "target_field": "weird.notice", "ignore_missing": true } },