From bac7ef71d826b3c786b239e2a1c289f114105071 Mon Sep 17 00:00:00 2001 From: William Wernert Date: Fri, 9 Jul 2021 10:55:11 -0400 Subject: [PATCH] Add logscan.source.ips field --- salt/elasticsearch/files/ingest/logscan | 2 ++ 1 file changed, 2 insertions(+) diff --git a/salt/elasticsearch/files/ingest/logscan b/salt/elasticsearch/files/ingest/logscan index 936d316f7..68c6aae44 100644 --- a/salt/elasticsearch/files/ingest/logscan +++ b/salt/elasticsearch/files/ingest/logscan @@ -8,6 +8,8 @@ { "date": { "field": "start_time", "target_field": "event.start", "formats": [ "ISO8601", "UNIX" ], "ignore_failures": true } }, { "date": { "field": "end_time", "target_field": "event.end", "formats": [ "ISO8601", "UNIX" ], "ignore_failures": true } }, { "rename": { "field": "source_ip", "target_field": "source.ip" } }, + { "append": { "field": "logsscan.source.ips", "value": "{{{source.ip}}}" } }, + { "rename": { "field": "source_ips", "target_field": "logscan.source.ips" } }, { "set": { "if": "model == kff", "field": "rule.name", "value": "LOGSCAN KFF MODEL THRESHOLD" } }, { "set": { "if": "model == kff", "field": "rule.description", "value": "High ratio of login failures in 5 minute window" } }, { "set": { "if": "model == kl", "field": "rule.name", "value": "LOGSCAN KL MODEL THRESHOLD" } },