From e2ee0db727e68b86113694dafd40c83b398aa56c Mon Sep 17 00:00:00 2001 From: OmerTirosh <74374518+OmerTirosh@users.noreply.github.com> Date: Tue, 24 Nov 2020 17:21:47 +0200 Subject: [PATCH] Ignore failure for rename processor Ignore failure for winlog.event_data.SubjectUserName rename processor. For some event ids (for example 4688), this field already been added in winlogbeat JS processor. Therefor, elastic throw [user.name] already exists error. --- salt/elasticsearch/files/ingest/win.eventlogs | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/salt/elasticsearch/files/ingest/win.eventlogs b/salt/elasticsearch/files/ingest/win.eventlogs index f7f9d6bac..3137e6bb5 100644 --- a/salt/elasticsearch/files/ingest/win.eventlogs +++ b/salt/elasticsearch/files/ingest/win.eventlogs @@ -6,7 +6,7 @@ { "set": { "if": "ctx.winlog?.computer_name != null", "field": "observer.name", "value": "{{winlog.computer_name}}", "override": true } }, { "set": { "field": "event.code", "value": "{{winlog.event_id}}", "override": true } }, { "set": { "field": "event.category", "value": "host", "override": true } }, - { "rename": { "field": "winlog.event_data.SubjectUserName", "target_field": "user.name", "ignore_missing": true } }, + { "rename": { "field": "winlog.event_data.SubjectUserName", "target_field": "user.name", "ignore_failure": true, "ignore_missing": true } }, { "rename": { "field": "winlog.event_data.User", "target_field": "user.name", "ignore_missing": true } } ] -} \ No newline at end of file +}