Files
securityonion/salt/elasticsearch/files/ingest/rita.dns
2023-01-24 18:00:34 +00:00

40 lines
664 B
Plaintext

{
"description": "RITA DNS",
"processors": [
{
"set": {
"field": "event.dataset",
"value": "dns",
"override": true
}
},
{
"csv": {
"field": "message",
"target_fields": [
"dns.question.name",
"dns.question.subdomain_count",
"dns.question.count"
]
}
},
{
"convert": {
"field": "dns.question.subdomain_count",
"type": "integer"
}
},
{
"convert": {
"field": "dns.question.count",
"type": "integer"
}
},
{
"pipeline": {
"name": "common"
}
}
]
}