From 93c3c86e2f070528b09de8bcad51e5bebd3f8055 Mon Sep 17 00:00:00 2001 From: Wes Lambert Date: Mon, 30 Mar 2020 14:24:01 +0000 Subject: [PATCH] update wazuh fields and category --- salt/elasticsearch/files/ingest/common | 1 + salt/elasticsearch/files/ingest/ossec | 6 +++--- 2 files changed, 4 insertions(+), 3 deletions(-) diff --git a/salt/elasticsearch/files/ingest/common b/salt/elasticsearch/files/ingest/common index de83ef4cf..3fb02a3bb 100644 --- a/salt/elasticsearch/files/ingest/common +++ b/salt/elasticsearch/files/ingest/common @@ -37,6 +37,7 @@ }, { "rename": { "field": "module", "target_field": "event.module", "ignore_missing": true } }, { "rename": { "field": "dataset", "target_field": "event.dataset", "ignore_missing": true } }, + { "rename": { "field": "category", "target_field": "event.category", "ignore_missing": true } }, { "remove": { "field": [ "index_name_prefix"], diff --git a/salt/elasticsearch/files/ingest/ossec b/salt/elasticsearch/files/ingest/ossec index ca20b9856..c1368e23f 100644 --- a/salt/elasticsearch/files/ingest/ossec +++ b/salt/elasticsearch/files/ingest/ossec @@ -30,9 +30,9 @@ { "rename": { "field": "data.win.eventdata.user", "target_field": "user.name", "ignore_missing": true } }, { "rename": { "field": "data.win.system.eventID", "target_field": "event.code", "ignore_missing": true } }, { "rename": { "field": "predecoder.program_name", "target_field": "process.name", "ignore_missing": true } }, - { "set": { "if": "ctx.rule.level == 1", "field": "category", "value": "None" } }, - { "set": { "if": "ctx.rule.level == 2", "field": "category", "value": "System low priority notification" } }, - { "set": { "if": "ctx.rule.level == 3", "field": "category", "value": "Successful/authorized event" } }, + { "set": { "if": "ctx.rule.level == 1", "field": "rule.category", "value": "None" } }, + { "set": { "if": "ctx.rule.level == 2", "field": "rule.category", "value": "System low priority notification" } }, + { "set": { "if": "ctx.rule.level == 3", "field": "rule.category", "value": "Successful/authorized event" } }, { "set": { "if": "ctx.rule.level == 4", "field": "rule.category", "value": "System low priority error" } }, { "set": { "if": "ctx.rule.level == 5", "field": "rule.category", "value": "User generated error" } }, { "set": { "if": "ctx.rule.level == 6", "field": "rule.category", "value": "Low relevance attack" } },