From 13faf637702f0ac1080b1df9fd682105340fef87 Mon Sep 17 00:00:00 2001 From: weslambert Date: Tue, 22 Nov 2022 12:07:15 -0500 Subject: [PATCH 1/2] Fix spelling for 'stun.class' field name --- salt/elasticsearch/files/ingest/zeek.stun | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/salt/elasticsearch/files/ingest/zeek.stun b/salt/elasticsearch/files/ingest/zeek.stun index f5e7d1baf..48f648d74 100644 --- a/salt/elasticsearch/files/ingest/zeek.stun +++ b/salt/elasticsearch/files/ingest/zeek.stun @@ -7,7 +7,7 @@ { "rename": { "field": "message2.is_orig", "target_field": "stun.is_orig", "ignore_missing": true } }, { "rename": { "field": "message2.trans_id", "target_field": "stun.id", "ignore_missing": true } }, { "rename": { "field": "message2.method", "target_field": "stun.method", "ignore_missing": true } }, - { "rename": { "field": "message2.class", "target_field": "stun.clas", "ignore_missing": true } }, + { "rename": { "field": "message2.class", "target_field": "stun.class", "ignore_missing": true } }, { "rename": { "field": "message2.attr_types", "target_field": "stun.attribute.types", "ignore_missing": true } }, { "rename": { "field": "message2.attr_vals", "target_field": "stun.attribute.values", "ignore_missing": true } }, { "pipeline": { "name": "zeek.common" } } From 6b77843e524717d91af916b032d504741fc51e1c Mon Sep 17 00:00:00 2001 From: weslambert Date: Tue, 22 Nov 2022 12:07:55 -0500 Subject: [PATCH 2/2] Fix format/speliing for 'enip.status_code' field name --- salt/elasticsearch/files/ingest/zeek.enip | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/salt/elasticsearch/files/ingest/zeek.enip b/salt/elasticsearch/files/ingest/zeek.enip index 456eb99d7..de4d2a989 100644 --- a/salt/elasticsearch/files/ingest/zeek.enip +++ b/salt/elasticsearch/files/ingest/zeek.enip @@ -8,7 +8,7 @@ { "rename": { "field": "message2.enip_command", "target_field": "enip.command", "ignore_missing": true } }, { "rename": { "field": "message2.length", "target_field": "enip.length", "ignore_missing": true } }, { "rename": { "field": "message2.session_handle", "target_field": "enip.session.handle", "ignore_missing": true } }, - { "rename": { "field": "message2.enip_status", "target_field": "enip.status.code", "ignore_missing": true } }, + { "rename": { "field": "message2.enip_status", "target_field": "enip.status_code", "ignore_missing": true } }, { "rename": { "field": "message2.sender_context", "target_field": "enip.sender.context", "ignore_missing": true } }, { "rename": { "field": "message2.options", "target_field": "enip.options", "ignore_missing": true } }, { "pipeline": { "name": "zeek.common" } }