zeek.common ingest parser fix

This commit is contained in:
Josh Brower
2020-05-21 14:35:25 -04:00
parent c74ace89ba
commit bff86ea802

View File

@@ -7,15 +7,7 @@
{ "dot_expander": { "field": "id.orig_p", "path": "message2", "ignore_failure": true } },
{ "dot_expander": { "field": "id.resp_h", "path": "message2", "ignore_failure": true } },
{ "dot_expander": { "field": "id.resp_p", "path": "message2", "ignore_failure": true } },
{"convert":{"field":"message2.id.orig_p","type":"string"}},
{"convert":{"field":"message2.id.resp_p","type":"string"}},
{"community_id": {"if": "ctx.network?.transport != null", "field":["message2.id.orig_h","message2.id.orig_p","message2.id.resp_h","message2.id.resp_p","network.transport"],"target_field":"network.community_id"}},
{"convert":{"field":"message2.id.orig_p","type":"integer"}},
{"convert":{"field":"message2.id.resp_p","type":"integer"}},
{ "rename": { "field": "message2.id.orig_h", "target_field": "source.ip", "ignore_missing": true } },
{ "rename": { "field": "message2.id.orig_p", "target_field": "source.port", "ignore_missing": true } },
{ "rename": { "field": "message2.id.resp_h", "target_field": "destination.ip", "ignore_missing": true } },