Set RITA event.dataset value explicitly

This commit is contained in:
Wes
2023-01-24 18:00:34 +00:00
parent 38ead7cb82
commit 4b9c92c53d
3 changed files with 6 additions and 6 deletions

View File

@@ -3,8 +3,8 @@
"processors": [ "processors": [
{ {
"set": { "set": {
"field": "_index", "field": "event.dataset",
"value": "so-rita", "value": "beacon",
"override": true "override": true
} }
}, },

View File

@@ -3,8 +3,8 @@
"processors": [ "processors": [
{ {
"set": { "set": {
"field": "_index", "field": "event.dataset",
"value": "so-rita", "value": "connection",
"override": true "override": true
} }
}, },

View File

@@ -3,8 +3,8 @@
"processors": [ "processors": [
{ {
"set": { "set": {
"field": "_index", "field": "event.dataset",
"value": "so-rita", "value": "dns",
"override": true "override": true
} }
}, },