diff --git a/salt/elasticsearch/files/ingest/zeek.dce_rpc b/salt/elasticsearch/files/ingest/zeek.dce_rpc index 50c9ff459..247946073 100644 --- a/salt/elasticsearch/files/ingest/zeek.dce_rpc +++ b/salt/elasticsearch/files/ingest/zeek.dce_rpc @@ -4,9 +4,9 @@ { "remove": { "field": ["host"], "ignore_failure": true } }, { "json": { "field": "message", "target_field": "message2", "ignore_failure": true } }, { "rename": { "field": "message2.rtt", "target_field": "event.duration", "ignore_missing": true } }, - { "rename": { "field": "message2.named_pipe", "target_field": "named_pipe", "ignore_missing": true } }, - { "rename": { "field": "message2.endpoint", "target_field": "endpoint", "ignore_missing": true } }, - { "rename": { "field": "message2.operation", "target_field": "operation", "ignore_missing": true } }, + { "rename": { "field": "message2.named_pipe", "target_field": "dce_rpc.named_pipe", "ignore_missing": true } }, + { "rename": { "field": "message2.endpoint", "target_field": "dce_rpc.endpoint", "ignore_missing": true } }, + { "rename": { "field": "message2.operation", "target_field": "dce_rpc.operation", "ignore_missing": true } }, { "pipeline": { "name": "zeek.common" } } ] }