Merge pull request #1002 from Security-Onion-Solutions/fix/strelka_observer

Add observer name for Strelka events
This commit is contained in:
weslambert
2020-07-14 13:39:52 -04:00
committed by GitHub

View File

@@ -19,6 +19,7 @@
}
}
},
{ "set": { "field": "observer.name", "value": "{{agent.name}}",
{ "remove": { "field": ["host", "path", "message", "scan.exiftool.keys"], "ignore_missing": true } },
{ "pipeline": { "name": "common" } }
]