Merge pull request #1473 from Security-Onion-Solutions/fix/logstash_output_wazuh

Remove dataset name since pipeline no longer in use
This commit is contained in:
weslambert
2020-10-07 11:49:40 -04:00
committed by GitHub

View File

@@ -7,7 +7,7 @@
output { output {
if [module] =~ "ossec" { if [module] =~ "ossec" {
elasticsearch { elasticsearch {
pipeline => "%{module}.%{dataset}" pipeline => "%{module}"
hosts => "{{ ES }}" hosts => "{{ ES }}"
index => "so-ossec-%{+YYYY.MM.dd}" index => "so-ossec-%{+YYYY.MM.dd}"
template_name => "so-ossec" template_name => "so-ossec"