From 5d5f5cf105e1330107796f0fb683ee2d63e1d789 Mon Sep 17 00:00:00 2001 From: Wes Lambert Date: Fri, 15 May 2020 18:19:05 +0000 Subject: [PATCH] update DCE/RPC parsing --- salt/elasticsearch/files/ingest/zeek.dce_rpc | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/salt/elasticsearch/files/ingest/zeek.dce_rpc b/salt/elasticsearch/files/ingest/zeek.dce_rpc index 50c9ff459..247946073 100644 --- a/salt/elasticsearch/files/ingest/zeek.dce_rpc +++ b/salt/elasticsearch/files/ingest/zeek.dce_rpc @@ -4,9 +4,9 @@ { "remove": { "field": ["host"], "ignore_failure": true } }, { "json": { "field": "message", "target_field": "message2", "ignore_failure": true } }, { "rename": { "field": "message2.rtt", "target_field": "event.duration", "ignore_missing": true } }, - { "rename": { "field": "message2.named_pipe", "target_field": "named_pipe", "ignore_missing": true } }, - { "rename": { "field": "message2.endpoint", "target_field": "endpoint", "ignore_missing": true } }, - { "rename": { "field": "message2.operation", "target_field": "operation", "ignore_missing": true } }, + { "rename": { "field": "message2.named_pipe", "target_field": "dce_rpc.named_pipe", "ignore_missing": true } }, + { "rename": { "field": "message2.endpoint", "target_field": "dce_rpc.endpoint", "ignore_missing": true } }, + { "rename": { "field": "message2.operation", "target_field": "dce_rpc.operation", "ignore_missing": true } }, { "pipeline": { "name": "zeek.common" } } ] }