mirror of
https://github.com/Security-Onion-Solutions/securityonion.git
synced 2025-12-06 17:22:49 +01:00
Merge pull request #359 from Security-Onion-Solutions/feature/strelka_ls
Add initial/basic Strelka config
This commit is contained in:
8
salt/logstash/conf/pipelines/eval/7200_strelka.conf
Normal file
8
salt/logstash/conf/pipelines/eval/7200_strelka.conf
Normal file
@@ -0,0 +1,8 @@
|
|||||||
|
filter {
|
||||||
|
if [type] =~ "strelka" {
|
||||||
|
json {
|
||||||
|
source => "message"
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
8
salt/logstash/conf/pipelines/search/7200_strelka.conf
Normal file
8
salt/logstash/conf/pipelines/search/7200_strelka.conf
Normal file
@@ -0,0 +1,8 @@
|
|||||||
|
filter {
|
||||||
|
if [type] =~ "strelka" {
|
||||||
|
json {
|
||||||
|
source => "message"
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
Reference in New Issue
Block a user