Add BSAP protocol

This commit is contained in:
lock-wire
2022-11-04 20:28:20 -07:00
committed by lock-wire
parent 5532577fdd
commit 85d30520ce
7 changed files with 89 additions and 0 deletions

View File

@@ -0,0 +1,9 @@
{
"description" : "zeek.bsap_serial_unknown",
"processors" : [
{ "remove": { "field": ["host"], "ignore_failure": true } },
{ "json": { "field": "message", "target_field": "message2", "ignore_failure": true } },
{ "rename": { "field": "message2.data", "target_field": "bsap.serial.unknown.data", "ignore_missing": true } },
{ "pipeline": { "name": "zeek.common" } }
]
}