diff --git a/salt/elasticsearch/files/ingest/strelka b/salt/elasticsearch/files/ingest/strelka index 8652fb912..39783c2ce 100644 --- a/salt/elasticsearch/files/ingest/strelka +++ b/salt/elasticsearch/files/ingest/strelka @@ -6,7 +6,7 @@ { "rename": { "field": "message2.scan", "target_field": "scan", "ignore_missing": true } }, { "rename": { "field": "message2.request", "target_field": "request", "ignore_missing": true } }, { "rename": { "field": "scan.hash", "target_field": "file.hash", "ignore_missing": true } }, - { "remove": { "field": ["host", "path"], "ignore_missing": true } }, + { "remove": { "field": ["host", "path", "agent"], "ignore_missing": true } }, { "pipeline": { "name": "common" } } ] }