Merge pull request #64 from weslambert/master

Logstash - Wazuh parsing updates
This commit is contained in:
Mike Reeves
2018-12-14 13:27:28 -05:00
committed by GitHub

View File

@@ -15,6 +15,7 @@ filter {
remove_tag => ["beat"]
add_field => { "sensor_name" => "%{[beat][name]}" }
add_field => { "syslog-host_from" => "%{[beat][name]}" }
remove_field => [ "beat", "prospector", "input", "offset" ]
}
}
if [type] =~ "ossec" {
@@ -22,6 +23,7 @@ filter {
rename => { "host" => "beat_host" }
remove_tag => ["beat"]
add_field => { "syslog-host_from" => "%{[beat][name]}" }
remove_field => [ "beat", "prospector", "input", "offset" ]
}
}
}