From f68972255961c6cd74f83274b8f2250eae6d1041 Mon Sep 17 00:00:00 2001 From: Wes Lambert Date: Thu, 10 Dec 2020 14:14:50 +0000 Subject: [PATCH] Add initial suricata.ftp_data pipeline --- salt/elasticsearch/files/ingest/suricata.ftp_data | 10 ++++++++++ 1 file changed, 10 insertions(+) create mode 100644 salt/elasticsearch/files/ingest/suricata.ftp_data diff --git a/salt/elasticsearch/files/ingest/suricata.ftp_data b/salt/elasticsearch/files/ingest/suricata.ftp_data new file mode 100644 index 000000000..2867fbab0 --- /dev/null +++ b/salt/elasticsearch/files/ingest/suricata.ftp_data @@ -0,0 +1,10 @@ +{ + "description" : "suricata.ftp_data", + "processors" : [ + { "rename": { "field": "message2.proto", "target_field": "network.transport", "ignore_missing": true } }, + { "rename": { "field": "message2.app_proto", "target_field": "network.protocol", "ignore_missing": true } }, + { "rename": { "field": "message2.ftp_data.command", "target_field": "ftp.command", "ignore_missing": true } }, + { "rename": { "field": "message2.ftp_data.filename","target_field": "ftp.argument", "ignore_missing": true } }, + { "pipeline": { "name": "common" } } + ] +}