mirror of
https://github.com/telekom-security/tpotce.git
synced 2025-07-02 01:27:27 -04:00
tweaking
Update logstash config for new Dicompot fields Revert Dionaea back to 0.8.0, latest master was unstable
This commit is contained in:
10
docker/elk/logstash/dist/logstash.conf
vendored
10
docker/elk/logstash/dist/logstash.conf
vendored
@ -314,9 +314,8 @@ filter {
|
||||
}
|
||||
mutate {
|
||||
rename => {
|
||||
"[Address][IP]" => "src_ip"
|
||||
"[Address][Port]" => "src_port"
|
||||
"[Address][Zone]" => "zone"
|
||||
"IP" => "src_ip"
|
||||
"Port" => "src_port"
|
||||
"AETitle" => "aetitle"
|
||||
"Command" => "input"
|
||||
"Files" => "files"
|
||||
@ -326,11 +325,6 @@ filter {
|
||||
"Version" => "version"
|
||||
}
|
||||
}
|
||||
if [Address] {
|
||||
mutate {
|
||||
remove_field => "[Address]"
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
# ElasticPot
|
||||
|
Reference in New Issue
Block a user