diff --git a/pillar/logstash/eval.sls b/pillar/logstash/eval.sls index e1b963e24..7f817ed39 100644 --- a/pillar/logstash/eval.sls +++ b/pillar/logstash/eval.sls @@ -11,7 +11,6 @@ logstash: - so/6600_winlogbeat_sysmon.conf - so/6700_winlogbeat.conf - so/7100_osquery_wel.conf - - so/7200_strelka.conf - so/8999_postprocess_rename_type.conf - so/9000_output_bro.conf.jinja - so/9002_output_import.conf.jinja diff --git a/salt/elasticsearch/files/ingest/strelka b/salt/elasticsearch/files/ingest/strelka new file mode 100644 index 000000000..8652fb912 --- /dev/null +++ b/salt/elasticsearch/files/ingest/strelka @@ -0,0 +1,12 @@ +{ + "description" : "strelka", + "processors" : [ + { "json": { "field": "message", "target_field": "message2", "ignore_failure": true } }, + { "rename": { "field": "message2.file", "target_field": "file", "ignore_missing": true } }, + { "rename": { "field": "message2.scan", "target_field": "scan", "ignore_missing": true } }, + { "rename": { "field": "message2.request", "target_field": "request", "ignore_missing": true } }, + { "rename": { "field": "scan.hash", "target_field": "file.hash", "ignore_missing": true } }, + { "remove": { "field": ["host", "path"], "ignore_missing": true } }, + { "pipeline": { "name": "common" } } + ] +}