Fix logstash logging issue, introduced with Sentrypeer 4.0.4

Similar to #1807
This commit is contained in:
t3chn0m4g3 2025-07-03 10:48:18 +02:00
parent c556d02a30
commit 6faf600d40
2 changed files with 14 additions and 8 deletions

View file

@ -698,12 +698,15 @@ filter {
remove_field => ["event_timestamp"] remove_field => ["event_timestamp"]
} }
mutate { mutate {
rename => { split => ["source_ip", ":"]
"source_ip" => "src_ip" rename => { "destination_ip" => "dest_ip" }
"destination_ip" => "dest_ip"
}
add_field => { "dest_port" => "5060" } add_field => { "dest_port" => "5060" }
} }
mutate {
add_field => { "src_ip" => "%{[source_ip][0]}" }
add_field => { "src_port" => "%{[source_ip][1]}" }
remove_field => ["source_ip"]
}
} }
# Tanner # Tanner

View file

@ -698,12 +698,15 @@ filter {
remove_field => ["event_timestamp"] remove_field => ["event_timestamp"]
} }
mutate { mutate {
rename => { split => ["source_ip", ":"]
"source_ip" => "src_ip" rename => { "destination_ip" => "dest_ip" }
"destination_ip" => "dest_ip"
}
add_field => { "dest_port" => "5060" } add_field => { "dest_port" => "5060" }
} }
mutate {
add_field => { "src_ip" => "%{[source_ip][0]}" }
add_field => { "src_port" => "%{[source_ip][1]}" }
remove_field => ["source_ip"]
}
} }
# Tanner # Tanner