mirror of
https://github.com/telekom-security/tpotce.git
synced 2025-07-02 01:27:27 -04:00
medpot tweaking
This commit is contained in:
7
docker/elk/logstash/dist/logstash.conf
vendored
7
docker/elk/logstash/dist/logstash.conf
vendored
@ -309,14 +309,9 @@ filter {
|
||||
"dest_port" => "2575"
|
||||
"dest_ip" => "${MY_EXTIP}"
|
||||
}
|
||||
rename => {
|
||||
"port" => "src_port"
|
||||
"ip" => "src_ip"
|
||||
}
|
||||
}
|
||||
date {
|
||||
match => [ "time", "yyyy.MM.dd HH:mm:ss" ]
|
||||
remove_field => ["time"]
|
||||
match => [ "timestamp", "ISO8601" ]
|
||||
}
|
||||
}
|
||||
|
||||
|
Reference in New Issue
Block a user