From e0570e1db7adfcf41e277d2d458b62e5c5e7a24a Mon Sep 17 00:00:00 2001 From: Wes Lambert Date: Tue, 7 Jul 2020 15:00:01 +0000 Subject: [PATCH] Add Zeek FUID for Strelka records --- salt/elasticsearch/files/ingest/strelka.file | 1 + 1 file changed, 1 insertion(+) diff --git a/salt/elasticsearch/files/ingest/strelka.file b/salt/elasticsearch/files/ingest/strelka.file index a2e08b799..ed80a4e5b 100644 --- a/salt/elasticsearch/files/ingest/strelka.file +++ b/salt/elasticsearch/files/ingest/strelka.file @@ -6,6 +6,7 @@ { "rename": { "field": "message2.scan", "target_field": "scan", "ignore_missing": true } }, { "rename": { "field": "message2.request", "target_field": "request", "ignore_missing": true } }, { "rename": { "field": "scan.hash", "target_field": "hash", "ignore_missing": true } }, + { "grok": { "field": "request.attributes.filename", "patterns": ["-%{WORD:log.id.fuid}-"] } }, { "remove": { "field": ["host", "path"], "ignore_missing": true } }, { "pipeline": { "name": "common" } } ]