-
Notifications
You must be signed in to change notification settings - Fork 4.9k
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
[Filebeat] Replace Suricata/Eve fields with aliases to ECS fields (#1…
…0377) This PR avoids duplicate data in documents ingested via the Suricata Eve fileset by replacing a few fields with aliases to ECS fields. This allows to maintain the full set of fields Suricata users may expect while at the same time reducing the size of the events. Also, the following non-related fixes are performed: - "http.response.status_code" was being set from a string and not an integer. - "user_agent.original" was being inadvertently removed by the user_agent processor. - Reformatted the ingest pipeline with standard JSON formatting.
- Loading branch information
Showing
9 changed files
with
626 additions
and
806 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Oops, something went wrong.