Helix - Final Parser Fixes

This commit is contained in:
Mike Reeves
2019-12-13 13:59:29 -05:00
parent 684ab737bf
commit e49de63460
2 changed files with 3 additions and 0 deletions

View File

@@ -27,9 +27,11 @@ filter {
#rename => { "%{[source_geo][country_code]}" => "srccountrycode" }
#rename => { "%{[destination_geo][country_code]}" => "dstcountrycode" }
rename => { "[beat_host][name]" => "sensor" }
copy => { "sensor" => "rawmsghostname" }
rename => { "message" => "rawmsg" }
#rename => { "event_type" => "program" }
copy => { "type" => "class" }
copy => { "class" => "program"}
rename => { "source_port" => "srcport" }
rename => { "destination_port" => "dstport" }
remove_field => ["source_ip", "destination_ip"]