mirror of
https://github.com/telekom-security/tpotce.git
synced 2025-11-02 13:32:53 +00:00
Compare commits
1 commit
d2fe64be19
...
80f2dc4904
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
80f2dc4904 |
2 changed files with 8 additions and 14 deletions
11
docker/elk/logstash/dist/http_output.conf
vendored
11
docker/elk/logstash/dist/http_output.conf
vendored
|
|
@ -698,15 +698,12 @@ filter {
|
||||||
remove_field => ["event_timestamp"]
|
remove_field => ["event_timestamp"]
|
||||||
}
|
}
|
||||||
mutate {
|
mutate {
|
||||||
split => ["source_ip", ":"]
|
rename => {
|
||||||
rename => { "destination_ip" => "dest_ip" }
|
"source_ip" => "src_ip"
|
||||||
|
"destination_ip" => "dest_ip"
|
||||||
|
}
|
||||||
add_field => { "dest_port" => "5060" }
|
add_field => { "dest_port" => "5060" }
|
||||||
}
|
}
|
||||||
mutate {
|
|
||||||
add_field => { "src_ip" => "%{[source_ip][0]}" }
|
|
||||||
add_field => { "src_port" => "%{[source_ip][1]}" }
|
|
||||||
remove_field => ["source_ip"]
|
|
||||||
}
|
|
||||||
}
|
}
|
||||||
|
|
||||||
# Tanner
|
# Tanner
|
||||||
|
|
|
||||||
11
docker/elk/logstash/dist/logstash.conf
vendored
11
docker/elk/logstash/dist/logstash.conf
vendored
|
|
@ -698,15 +698,12 @@ filter {
|
||||||
remove_field => ["event_timestamp"]
|
remove_field => ["event_timestamp"]
|
||||||
}
|
}
|
||||||
mutate {
|
mutate {
|
||||||
split => ["source_ip", ":"]
|
rename => {
|
||||||
rename => { "destination_ip" => "dest_ip" }
|
"source_ip" => "src_ip"
|
||||||
|
"destination_ip" => "dest_ip"
|
||||||
|
}
|
||||||
add_field => { "dest_port" => "5060" }
|
add_field => { "dest_port" => "5060" }
|
||||||
}
|
}
|
||||||
mutate {
|
|
||||||
add_field => { "src_ip" => "%{[source_ip][0]}" }
|
|
||||||
add_field => { "src_port" => "%{[source_ip][1]}" }
|
|
||||||
remove_field => ["source_ip"]
|
|
||||||
}
|
|
||||||
}
|
}
|
||||||
|
|
||||||
# Tanner
|
# Tanner
|
||||||
|
|
|
||||||
Loading…
Reference in a new issue