mirror of
https://github.com/Security-Onion-Solutions/securityonion.git
synced 2025-12-10 11:12:51 +01:00
Only append source.ip to logscan.source.ips if it's been created
This commit is contained in:
@@ -11,8 +11,8 @@
|
|||||||
{ "remove": { "field": "start_time", "ignore_missing": true } },
|
{ "remove": { "field": "start_time", "ignore_missing": true } },
|
||||||
{ "remove": { "field": "end_time", "ignore_missing": true } },
|
{ "remove": { "field": "end_time", "ignore_missing": true } },
|
||||||
{ "rename": { "field": "source_ip", "target_field": "source.ip", "ignore_missing": true } },
|
{ "rename": { "field": "source_ip", "target_field": "source.ip", "ignore_missing": true } },
|
||||||
{ "append": { "field": "logscan.source.ips", "value": "{{{source.ip}}}", "ignore_failure": true } },
|
|
||||||
{ "rename": { "field": "top_source_ips", "target_field": "logscan.source.ips", "ignore_missing": true } },
|
{ "rename": { "field": "top_source_ips", "target_field": "logscan.source.ips", "ignore_missing": true } },
|
||||||
|
{ "append": { "if": "ctx.source != null", "field": "logscan.source.ips", "value": "{{{source.ip}}}", "ignore_failure": true } },
|
||||||
{ "set": { "if": "ctx.model == 'k1'", "field": "rule.name", "value": "LOGSCAN K1 MODEL THRESHOLD" } },
|
{ "set": { "if": "ctx.model == 'k1'", "field": "rule.name", "value": "LOGSCAN K1 MODEL THRESHOLD" } },
|
||||||
{ "set": { "if": "ctx.model == 'k1'", "field": "rule.description", "value": "High number of logins from single IP in 1 minute window" } },
|
{ "set": { "if": "ctx.model == 'k1'", "field": "rule.description", "value": "High number of logins from single IP in 1 minute window" } },
|
||||||
{ "set": { "if": "ctx.model == 'k5'", "field": "rule.name", "value": "LOGSCAN K5 MODEL THRESHOLD" } },
|
{ "set": { "if": "ctx.model == 'k5'", "field": "rule.name", "value": "LOGSCAN K5 MODEL THRESHOLD" } },
|
||||||
|
|||||||
Reference in New Issue
Block a user