From b75bd35bc2488acabf488e9e3f7bfe36ceb0a3bb Mon Sep 17 00:00:00 2001 From: Wes Lambert Date: Tue, 3 Mar 2020 21:19:54 +0000 Subject: [PATCH 1/2] remove Strelka from LS PL --- pillar/logstash/eval.sls | 1 - 1 file changed, 1 deletion(-) diff --git a/pillar/logstash/eval.sls b/pillar/logstash/eval.sls index e1b963e24..7f817ed39 100644 --- a/pillar/logstash/eval.sls +++ b/pillar/logstash/eval.sls @@ -11,7 +11,6 @@ logstash: - so/6600_winlogbeat_sysmon.conf - so/6700_winlogbeat.conf - so/7100_osquery_wel.conf - - so/7200_strelka.conf - so/8999_postprocess_rename_type.conf - so/9000_output_bro.conf.jinja - so/9002_output_import.conf.jinja From b1203cfb9ff55cc9f2d6c31104e172e5600edec1 Mon Sep 17 00:00:00 2001 From: Wes Lambert Date: Tue, 3 Mar 2020 21:20:45 +0000 Subject: [PATCH 2/2] add initial Strelka ingest config --- salt/elasticsearch/files/ingest/strelka | 12 ++++++++++++ 1 file changed, 12 insertions(+) create mode 100644 salt/elasticsearch/files/ingest/strelka diff --git a/salt/elasticsearch/files/ingest/strelka b/salt/elasticsearch/files/ingest/strelka new file mode 100644 index 000000000..8652fb912 --- /dev/null +++ b/salt/elasticsearch/files/ingest/strelka @@ -0,0 +1,12 @@ +{ + "description" : "strelka", + "processors" : [ + { "json": { "field": "message", "target_field": "message2", "ignore_failure": true } }, + { "rename": { "field": "message2.file", "target_field": "file", "ignore_missing": true } }, + { "rename": { "field": "message2.scan", "target_field": "scan", "ignore_missing": true } }, + { "rename": { "field": "message2.request", "target_field": "request", "ignore_missing": true } }, + { "rename": { "field": "scan.hash", "target_field": "file.hash", "ignore_missing": true } }, + { "remove": { "field": ["host", "path"], "ignore_missing": true } }, + { "pipeline": { "name": "common" } } + ] +}