diff --git a/salt/elasticsearch/files/ingest/global@custom b/salt/elasticsearch/files/ingest/global@custom index ab1418cd2..bfd58d750 100644 --- a/salt/elasticsearch/files/ingest/global@custom +++ b/salt/elasticsearch/files/ingest/global@custom @@ -1,5 +1,5 @@ { - "version": 3, + "version": 4, "_meta": { "managed_by": "securityonion", "managed": true @@ -177,6 +177,32 @@ "description": "Extract IPs from Elastic Agent events (host.ip) and adds them to related.ip" } }, + { + "trim": { + "if": "ctx.event?.dataset == 'system.auth'", + "description": "Grok leaves a leading space on 'invalid user' names (elastic/integrations#12174) and, before 2.23.2, sudo padding", + "field": "user.name", + "ignore_missing": true, + "ignore_failure": true + } + }, + { + "trim": { + "if": "ctx.event?.dataset == 'system.auth'", + "description": "Appended from the untrimmed user.name", + "field": "related.user", + "ignore_missing": true, + "ignore_failure": true + } + }, + { + "script": { + "if": "ctx.event?.dataset == 'system.auth' && ctx.related?.user instanceof List", + "description": "Dedupe after trimming", + "source": "ctx.related.user = new ArrayList(new LinkedHashSet(ctx.related.user));", + "ignore_failure": true + } + }, { "script": { "description": "Snapshot event.ingested into _tmp.event_ingested_pre_fleet before .fleet_final_pipeline-1 overwrites it with ES ingest time", diff --git a/salt/elasticsearch/files/ingest/logs-system.auth@custom b/salt/elasticsearch/files/ingest/logs-system.auth@custom deleted file mode 100644 index 19e3b9a3d..000000000 --- a/salt/elasticsearch/files/ingest/logs-system.auth@custom +++ /dev/null @@ -1,34 +0,0 @@ -{ - "version": 1, - "_meta": { - "managed_by": "securityonion", - "managed": true - }, - "description": "Custom pipeline for the System integration's auth data stream.", - "processors": [ - { - "trim": { - "description": "Grok leaves a leading space on 'invalid user' names (elastic/integrations#12174) and, before 2.23.2, sudo padding", - "field": "user.name", - "ignore_missing": true, - "ignore_failure": true - } - }, - { - "trim": { - "description": "Appended from the untrimmed user.name", - "field": "related.user", - "ignore_missing": true, - "ignore_failure": true - } - }, - { - "script": { - "description": "Dedupe after trimming", - "if": "ctx.related?.user instanceof List", - "source": "ctx.related.user = new ArrayList(new LinkedHashSet(ctx.related.user));", - "ignore_failure": true - } - } - ] -}