Fix module,dataset rename

This commit is contained in:
Wes Lambert
2020-10-10 00:01:37 +00:00
parent 69a04dedd3
commit b55ffa44f8
2 changed files with 8 additions and 4 deletions

View File

@@ -52,8 +52,8 @@
}, },
{ "set": { "field": "_index", "value": "so-firewall", "override": true } }, { "set": { "field": "_index", "value": "so-firewall", "override": true } },
{ "set": { "if": "ctx.network?.transport_id == '0'", "field": "network.transport", "value": "icmp", "override": true } }, { "set": { "if": "ctx.network?.transport_id == '0'", "field": "network.transport", "value": "icmp", "override": true } },
{ "set": { "field": "event.module", "value": "pfsense", "override": true } }, { "set": { "field": "module", "value": "pfsense", "override": true } },
{ "set": { "field": "event.dataset", "value": "firewall", "override": true } }, { "set": { "field": "dataset", "value": "firewall", "override": true } },
{ "remove": { "field": ["real_message", "ip_sub_msg", "firewall.sub_message"], "ignore_failure": true } }, { "remove": { "field": ["real_message", "ip_sub_msg", "firewall.sub_message"], "ignore_failure": true } },
{ "append": { "field": "tags", "value": ["pfsense"] } } { "append": { "field": "tags", "value": ["pfsense"] } }
] ]

View File

@@ -257,7 +257,11 @@
"type":"object", "type":"object",
"dynamic": true "dynamic": true
}, },
"irc":{ "ip":{
"type":"object",
"dynamic": true
},
"irc":{
"type":"object", "type":"object",
"dynamic": true "dynamic": true
}, },
@@ -273,7 +277,7 @@
"type":"object", "type":"object",
"dynamic": true "dynamic": true
}, },
"message":{ "message":{
"type":"text", "type":"text",
"fields":{ "fields":{
"keyword":{ "keyword":{