mirror of
https://github.com/Security-Onion-Solutions/securityonion.git
synced 2025-12-06 17:22:49 +01:00
Helix - Final Parser Fixes
This commit is contained in:
@@ -27,9 +27,11 @@ filter {
|
|||||||
#rename => { "%{[source_geo][country_code]}" => "srccountrycode" }
|
#rename => { "%{[source_geo][country_code]}" => "srccountrycode" }
|
||||||
#rename => { "%{[destination_geo][country_code]}" => "dstcountrycode" }
|
#rename => { "%{[destination_geo][country_code]}" => "dstcountrycode" }
|
||||||
rename => { "[beat_host][name]" => "sensor" }
|
rename => { "[beat_host][name]" => "sensor" }
|
||||||
|
copy => { "sensor" => "rawmsghostname" }
|
||||||
rename => { "message" => "rawmsg" }
|
rename => { "message" => "rawmsg" }
|
||||||
#rename => { "event_type" => "program" }
|
#rename => { "event_type" => "program" }
|
||||||
copy => { "type" => "class" }
|
copy => { "type" => "class" }
|
||||||
|
copy => { "class" => "program"}
|
||||||
rename => { "source_port" => "srcport" }
|
rename => { "source_port" => "srcport" }
|
||||||
rename => { "destination_port" => "dstport" }
|
rename => { "destination_port" => "dstport" }
|
||||||
remove_field => ["source_ip", "destination_ip"]
|
remove_field => ["source_ip", "destination_ip"]
|
||||||
|
|||||||
@@ -153,6 +153,7 @@ if (whiptail_you_sure) ; then
|
|||||||
RULESETUP=ETOPEN
|
RULESETUP=ETOPEN
|
||||||
NSMSETUP=BASIC
|
NSMSETUP=BASIC
|
||||||
HNSENSOR=inherit
|
HNSENSOR=inherit
|
||||||
|
LS_HEAP_SIZE="1000m"
|
||||||
calculate_useable_cores
|
calculate_useable_cores
|
||||||
whiptail_make_changes
|
whiptail_make_changes
|
||||||
set_hostname
|
set_hostname
|
||||||
|
|||||||
Reference in New Issue
Block a user