From b1203cfb9ff55cc9f2d6c31104e172e5600edec1 Mon Sep 17 00:00:00 2001 From: Wes Lambert Date: Tue, 3 Mar 2020 21:20:45 +0000 Subject: [PATCH] add initial Strelka ingest config --- salt/elasticsearch/files/ingest/strelka | 12 ++++++++++++ 1 file changed, 12 insertions(+) create mode 100644 salt/elasticsearch/files/ingest/strelka diff --git a/salt/elasticsearch/files/ingest/strelka b/salt/elasticsearch/files/ingest/strelka new file mode 100644 index 000000000..8652fb912 --- /dev/null +++ b/salt/elasticsearch/files/ingest/strelka @@ -0,0 +1,12 @@ +{ + "description" : "strelka", + "processors" : [ + { "json": { "field": "message", "target_field": "message2", "ignore_failure": true } }, + { "rename": { "field": "message2.file", "target_field": "file", "ignore_missing": true } }, + { "rename": { "field": "message2.scan", "target_field": "scan", "ignore_missing": true } }, + { "rename": { "field": "message2.request", "target_field": "request", "ignore_missing": true } }, + { "rename": { "field": "scan.hash", "target_field": "file.hash", "ignore_missing": true } }, + { "remove": { "field": ["host", "path"], "ignore_missing": true } }, + { "pipeline": { "name": "common" } } + ] +}