From a5ff21c5284ca7263ad579cc6c7bbd12d7ac8b01 Mon Sep 17 00:00:00 2001 From: Wes Lambert Date: Tue, 17 Mar 2020 15:20:46 +0000 Subject: [PATCH] remove agent field for non-Wazuh logs --- salt/elasticsearch/files/ingest/strelka | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/salt/elasticsearch/files/ingest/strelka b/salt/elasticsearch/files/ingest/strelka index 8652fb912..39783c2ce 100644 --- a/salt/elasticsearch/files/ingest/strelka +++ b/salt/elasticsearch/files/ingest/strelka @@ -6,7 +6,7 @@ { "rename": { "field": "message2.scan", "target_field": "scan", "ignore_missing": true } }, { "rename": { "field": "message2.request", "target_field": "request", "ignore_missing": true } }, { "rename": { "field": "scan.hash", "target_field": "file.hash", "ignore_missing": true } }, - { "remove": { "field": ["host", "path"], "ignore_missing": true } }, + { "remove": { "field": ["host", "path", "agent"], "ignore_missing": true } }, { "pipeline": { "name": "common" } } ] }