mirror of
https://github.com/Security-Onion-Solutions/securityonion.git
synced 2025-12-08 18:22:47 +01:00
Modify Logstash Elastic Agent output to accomodate for events with and without 'metadata.pipeline'
This commit is contained in:
@@ -1,5 +1,18 @@
|
|||||||
output {
|
output {
|
||||||
if "elastic-agent" in [tags] and "import" not in [tags] {
|
if "elastic-agent" in [tags] and "import" not in [tags] {
|
||||||
|
if [metadata][pipeline] {
|
||||||
|
elasticsearch {
|
||||||
|
hosts => "{{ GLOBALS.manager }}"
|
||||||
|
ecs_compatibility => v8
|
||||||
|
data_stream => true
|
||||||
|
user => "{{ ES_USER }}"
|
||||||
|
password => "{{ ES_PASS }}"
|
||||||
|
pipeline => "%{[metadata][pipeline]}"
|
||||||
|
ssl => true
|
||||||
|
ssl_certificate_verification => false
|
||||||
|
}
|
||||||
|
}
|
||||||
|
else {
|
||||||
elasticsearch {
|
elasticsearch {
|
||||||
hosts => "{{ GLOBALS.manager }}"
|
hosts => "{{ GLOBALS.manager }}"
|
||||||
ecs_compatibility => v8
|
ecs_compatibility => v8
|
||||||
@@ -10,5 +23,6 @@ output {
|
|||||||
ssl_certificate_verification => false
|
ssl_certificate_verification => false
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user