Add exclude filter for logs for when there are no results from analysis

This commit is contained in:
weslambert
2022-03-24 13:03:03 -04:00
committed by GitHub
parent 8a56c88773
commit fbc86f43ec

View File

@@ -269,7 +269,7 @@ filebeat.inputs:
- type: filestream
paths:
- /nsm/rita/beacons.csv
exclude_lines: ['^Score', '^Source', '^Domain']
exclude_lines: ['^Score', '^Source', '^Domain', '^No results']
fields:
module: rita
dataset: beacon
@@ -285,7 +285,7 @@ filebeat.inputs:
paths:
- /nsm/rita/long-connections.csv
- /nsm/rita/open-connections.csv
exclude_lines: ['^Source']
exclude_lines: ['^Source', '^No results']
fields:
module: rita
dataset: connection
@@ -300,7 +300,7 @@ filebeat.inputs:
- type: filestream
paths:
- /nsm/rita/exploded-dns.csv
exclude_lines: ['^Domain']
exclude_lines: ['^Domain', '^No results']
fields:
module: rita
dataset: dns