mirror of
https://github.com/Security-Onion-Solutions/securityonion.git
synced 2025-12-06 09:12:45 +01:00
Add initia/basic Strelka config
This commit is contained in:
8
salt/logstash/conf/pipelines/eval/7200_strelka.conf
Normal file
8
salt/logstash/conf/pipelines/eval/7200_strelka.conf
Normal file
@@ -0,0 +1,8 @@
|
||||
filter {
|
||||
if [type] =~ "strelka" {
|
||||
json {
|
||||
source => "message"
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
8
salt/logstash/conf/pipelines/search/7200_strelka.conf
Normal file
8
salt/logstash/conf/pipelines/search/7200_strelka.conf
Normal file
@@ -0,0 +1,8 @@
|
||||
filter {
|
||||
if [type] =~ "strelka" {
|
||||
json {
|
||||
source => "message"
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user