mirror of
https://github.com/Security-Onion-Solutions/securityonion.git
synced 2025-12-06 17:22:49 +01:00
fix zeek opcua pipelines
This commit is contained in:
@@ -1,5 +1,5 @@
|
||||
{
|
||||
"description" : "zeek.opcua",
|
||||
"description" : "zeek.opcua_binary",
|
||||
"processors" : [
|
||||
{ "remove": { "field": ["host"], "ignore_failure": true } },
|
||||
{ "json": { "field": "message", "target_field": "message2", "ignore_failure": true} },
|
||||
@@ -1,5 +1,5 @@
|
||||
{
|
||||
"description" : "zeek.opcua.activate_session",
|
||||
"description" : "zeek.opcua_binary_activate_session",
|
||||
"processors" : [
|
||||
{ "remove": { "field": ["host"], "ignore_failure": true } },
|
||||
{ "json": { "field": "message", "target_field": "message2", "ignore_failure": true} },
|
||||
@@ -1,5 +1,5 @@
|
||||
{
|
||||
"description" : "zeek.opcua.activate_session_client_software_cert",
|
||||
"description" : "zeek.opcua_binary_activate_session_client_software_cert",
|
||||
"processors" : [
|
||||
{ "remove": { "field": ["host"], "ignore_failure": true } },
|
||||
{ "json": { "field": "message", "target_field": "message2", "ignore_failure": true} },
|
||||
@@ -1,5 +1,5 @@
|
||||
{
|
||||
"description" : "zeek.opcua.activate_session_diagnostic_info",
|
||||
"description" : "zeek.opcua_binary_activate_session_diagnostic_info",
|
||||
"processors" : [
|
||||
{ "remove": { "field": ["host"], "ignore_failure": true } },
|
||||
{ "json": { "field": "message", "target_field": "message2", "ignore_failure": true} },
|
||||
@@ -1,5 +1,5 @@
|
||||
{
|
||||
"description" : "zeek.opcua.activate_session_locale_id",
|
||||
"description" : "zeek.opcua_binary_activate_session_locale_id",
|
||||
"processors" : [
|
||||
{ "remove": { "field": ["host"], "ignore_failure": true } },
|
||||
{ "json": { "field": "message", "target_field": "message2", "ignore_failure": true} },
|
||||
@@ -1,5 +1,5 @@
|
||||
{
|
||||
"description" : "zeek.opcua.browse",
|
||||
"description" : "zeek.opcua_binary_browse",
|
||||
"processors" : [
|
||||
{ "remove": { "field": ["host"], "ignore_failure": true } },
|
||||
{ "json": { "field": "message", "target_field": "message2", "ignore_failure": true} },
|
||||
@@ -1,5 +1,5 @@
|
||||
{
|
||||
"description" : "zeek.opcua.browse_description",
|
||||
"description" : "zeek.opcua_binary_browse_description",
|
||||
"processors" : [
|
||||
{ "remove": { "field": ["host"], "ignore_failure": true } },
|
||||
{ "json": { "field": "message", "target_field": "message2", "ignore_failure": true } },
|
||||
@@ -1,5 +1,5 @@
|
||||
{
|
||||
"description" : "zeek.opcua_browse_response_references",
|
||||
"description" : "zeek.opcua_binary_browse_response_references",
|
||||
"processors" : [
|
||||
{ "remove": { "field": ["host"], "ignore_failure": true } },
|
||||
{ "json": { "field": "message", "target_field": "message2", "ignore_failure": true} },
|
||||
@@ -1,5 +1,5 @@
|
||||
{
|
||||
"description" : "zeek.opcua_browse_result",
|
||||
"description" : "zeek.opcua_binary_browse_result",
|
||||
"processors" : [
|
||||
{ "remove": { "field": ["host"], "ignore_failure": true } },
|
||||
{ "json": { "field": "message", "target_field": "message2", "ignore_failure": true} },
|
||||
@@ -1,5 +1,5 @@
|
||||
{
|
||||
"description" : "zeek.opcua_create_session",
|
||||
"description" : "zeek.opcua_binary_create_session",
|
||||
"processors" : [
|
||||
{ "remove": { "field": ["host"], "ignore_failure": true } },
|
||||
{ "json": { "field": "message", "target_field": "message2", "ignore_failure": true} },
|
||||
@@ -1,5 +1,5 @@
|
||||
{
|
||||
"description" : "zeek.opcua",
|
||||
"description" : "zeek.opcua_binary",
|
||||
"processors" : [
|
||||
{ "remove": { "field": ["host"], "ignore_failure": true } },
|
||||
{ "json": { "field": "message", "target_field": "message2", "ignore_failure": true} },
|
||||
@@ -1,5 +1,5 @@
|
||||
{
|
||||
"description" : "zeek.opcua_create_session_user_token",
|
||||
"description" : "zeek.opcua_binary_create_session_user_token",
|
||||
"processors" : [
|
||||
{ "remove": { "field": ["host"], "ignore_failure": true } },
|
||||
{ "json": { "field": "message", "target_field": "message2", "ignore_failure": true} },
|
||||
@@ -1,5 +1,5 @@
|
||||
{
|
||||
"description" : "zeek.opcua_create_subscription",
|
||||
"description" : "zeek.opcua_binary_create_subscription",
|
||||
"processors" : [
|
||||
{ "remove": { "field": ["host"], "ignore_failure": true } },
|
||||
{ "json": { "field": "message", "target_field": "message2", "ignore_failure": true} },
|
||||
@@ -1,5 +1,5 @@
|
||||
{
|
||||
"description" : "zeek.opcua_get_endpoints",
|
||||
"description" : "zeek.opcua_binary_get_endpoints",
|
||||
"processors" : [
|
||||
{ "remove": { "field": ["host"], "ignore_failure": true } },
|
||||
{ "json": { "field": "message", "target_field": "message2", "ignore_failure": true} },
|
||||
@@ -1,5 +1,5 @@
|
||||
{
|
||||
"description" : "zeek.opcua_get_endpoints_description",
|
||||
"description" : "zeek.opcua_binary_get_endpoints_description",
|
||||
"processors" : [
|
||||
{ "remove": { "field": ["host"], "ignore_failure": true } },
|
||||
{ "json": { "field": "message", "target_field": "message2", "ignore_failure": true} },
|
||||
@@ -1,5 +1,5 @@
|
||||
{
|
||||
"description" : "zeek.opcua_get_endpoints_user_token",
|
||||
"description" : "zeek.opcua_binary_get_endpoints_user_token",
|
||||
"processors" : [
|
||||
{ "remove": { "field": ["host"], "ignore_failure": true } },
|
||||
{ "json": { "field": "message", "target_field": "message2", "ignore_failure": true} },
|
||||
@@ -1,5 +1,5 @@
|
||||
{
|
||||
"description" : "zeek.opcua_opensecure_channel",
|
||||
"description" : "zeek.opcua_binary_opensecure_channel",
|
||||
"processors" : [
|
||||
{ "remove": { "field": ["host"], "ignore_failure": true } },
|
||||
{ "json": { "field": "message", "target_field": "message2", "ignore_failure": true} },
|
||||
@@ -1,5 +1,5 @@
|
||||
{
|
||||
"description" : "zeek.opcua_read",
|
||||
"description" : "zeek.opcua_binary_read",
|
||||
"processors" : [
|
||||
{ "remove": { "field": ["host"], "ignore_failure": true } },
|
||||
{ "json": { "field": "message", "target_field": "message2", "ignore_failure": true} },
|
||||
@@ -1,5 +1,5 @@
|
||||
{
|
||||
"description" : "zeek.opcua_read_nodes_to_read",
|
||||
"description" : "zeek.opcua_binary_read_nodes_to_read",
|
||||
"processors" : [
|
||||
{ "remove": { "field": ["host"], "ignore_failure": true } },
|
||||
{ "json": { "field": "message", "target_field": "message2", "ignore_failure": true} },
|
||||
@@ -1,5 +1,5 @@
|
||||
{
|
||||
"description" : "zeek.opcua_read_results",
|
||||
"description" : "zeek.opcua_binary_read_results",
|
||||
"processors" : [
|
||||
{ "remove": { "field": ["host"], "ignore_failure": true } },
|
||||
{ "json": { "field": "message", "target_field": "message2", "ignore_failure": true} },
|
||||
@@ -1,5 +1,5 @@
|
||||
{
|
||||
"description" : "zeek.opcua_read_results_link",
|
||||
"description" : "zeek.opcua_binary_read_results_link",
|
||||
"processors" : [
|
||||
{ "remove": { "field": ["host"], "ignore_failure": true } },
|
||||
{ "json": { "field": "message", "target_field": "message2", "ignore_failure": true} },
|
||||
@@ -1,5 +1,5 @@
|
||||
{
|
||||
"description" : "zeek.opcua_stats_code_detail",
|
||||
"description" : "zeek.opcua_binary_stats_code_detail",
|
||||
"processors" : [
|
||||
{ "remove": { "field": ["host"], "ignore_failure": true } },
|
||||
{ "json": { "field": "message", "target_field": "message2", "ignore_failure": true} },
|
||||
Reference in New Issue
Block a user