Helix - Final Parser Fixes

This commit is contained in:
Mike Reeves
2019-12-13 13:59:29 -05:00
parent 684ab737bf
commit e49de63460
2 changed files with 3 additions and 0 deletions

View File

@@ -27,9 +27,11 @@ filter {
#rename => { "%{[source_geo][country_code]}" => "srccountrycode" } #rename => { "%{[source_geo][country_code]}" => "srccountrycode" }
#rename => { "%{[destination_geo][country_code]}" => "dstcountrycode" } #rename => { "%{[destination_geo][country_code]}" => "dstcountrycode" }
rename => { "[beat_host][name]" => "sensor" } rename => { "[beat_host][name]" => "sensor" }
copy => { "sensor" => "rawmsghostname" }
rename => { "message" => "rawmsg" } rename => { "message" => "rawmsg" }
#rename => { "event_type" => "program" } #rename => { "event_type" => "program" }
copy => { "type" => "class" } copy => { "type" => "class" }
copy => { "class" => "program"}
rename => { "source_port" => "srcport" } rename => { "source_port" => "srcport" }
rename => { "destination_port" => "dstport" } rename => { "destination_port" => "dstport" }
remove_field => ["source_ip", "destination_ip"] remove_field => ["source_ip", "destination_ip"]

View File

@@ -153,6 +153,7 @@ if (whiptail_you_sure) ; then
RULESETUP=ETOPEN RULESETUP=ETOPEN
NSMSETUP=BASIC NSMSETUP=BASIC
HNSENSOR=inherit HNSENSOR=inherit
LS_HEAP_SIZE="1000m"
calculate_useable_cores calculate_useable_cores
whiptail_make_changes whiptail_make_changes
set_hostname set_hostname