diff --git a/salt/filebeat/etc/filebeat.yml b/salt/filebeat/etc/filebeat.yml index 7efa391e2..62a45e9c4 100644 --- a/salt/filebeat/etc/filebeat.yml +++ b/salt/filebeat/etc/filebeat.yml @@ -269,7 +269,7 @@ filebeat.inputs: - type: filestream paths: - /nsm/rita/beacons.csv - exclude_lines: ['^Score', '^Source', '^Domain'] + exclude_lines: ['^Score', '^Source', '^Domain', '^No results'] fields: module: rita dataset: beacon @@ -285,7 +285,7 @@ filebeat.inputs: paths: - /nsm/rita/long-connections.csv - /nsm/rita/open-connections.csv - exclude_lines: ['^Source'] + exclude_lines: ['^Source', '^No results'] fields: module: rita dataset: connection @@ -300,7 +300,7 @@ filebeat.inputs: - type: filestream paths: - /nsm/rita/exploded-dns.csv - exclude_lines: ['^Domain'] + exclude_lines: ['^Domain', '^No results'] fields: module: rita dataset: dns