Imported logs are sent to so-import index on eval installations

This commit is contained in:
Jason Ertel
2020-07-14 22:59:42 -04:00
parent b53ce392ef
commit 9dc1151347

View File

@@ -127,7 +127,7 @@ filebeat.inputs:
imported: true
processors:
- add_tags:
tags: [import]
tags: ["import"]
- dissect:
tokenizer: "/nsm/import/%{import.id}/zeek/logs/%{import.file}"
field: "log.file.path"
@@ -167,7 +167,7 @@ filebeat.inputs:
imported: true
processors:
- add_tags:
tags: [import]
tags: ["import"]
- dissect:
tokenizer: "/nsm/import/%{import.id}/suricata/%{import.file}"
field: "log.file.path"
@@ -260,6 +260,9 @@ output.elasticsearch:
pipelines:
- pipeline: "%{[module]}.%{[dataset]}"
indices:
- index: "so-import-%{+yyyy.MM.dd}"
when.contains:
tags: "import"
- index: "so-zeek-%{+yyyy.MM.dd}"
when.contains:
module: "zeek"