Osquery Parsing fix

This commit is contained in:
Josh Brower
2020-08-18 15:54:11 -04:00
parent ca84ae43ef
commit d4f7a07f85

View File

@@ -18,8 +18,8 @@
"source": "def dict = ['result': new HashMap()]; for (entry in ctx['message2'].entrySet()) { dict['result'][entry.getKey()] = entry.getValue(); } ctx['osquery'] = dict; "
}
},
{ "set": { "field": "event.module", "value": "osquery" } },
{ "set": { "field": "event.dataset", "value": "{{osquery.result.name}}"} },
{ "set": { "field": "event.module", "value": "osquery", "override": false } },
{ "set": { "field": "event.dataset", "value": "{{osquery.result.name}}", "override": false} },
{ "pipeline": { "name": "common" } }
]
}