Security-Onion-Solutions / security-onion

Security Onion 16.04 - Linux distro for threat hunting, enterprise security monitoring, and log management
https://securityonion.net
3.06k stars 519 forks source link

securityonion-elastic: adjust bro_notice parsing #1724

Closed dougburks closed 4 years ago

dougburks commented 4 years ago

Looks like at some point desc was changed to file_desc and mime was changed to file_mime_type, so we need to update our parsers to reflect that.

image

Current ingest:

    { "rename":         { "field": "message2.mime",             "target_field": "file_mime_type",       "ignore_missing": true  } },
    { "rename":         { "field": "message2.desc",             "target_field": "file_description",     "ignore_missing": true  } },

Current logstash:

1109_preprocess_bro_notice.conf:
rename => { "mime" => "file_mime_type" }
rename => { "desc" => "file_description" }
dougburks commented 4 years ago

To test, please verify that file_mime_type and file_description are being parsed properly in both traditional Logstash parsing and Elasticsearch ingest node parsing.

dougburks commented 4 years ago

Published: https://blog.securityonion.net/2020/03/elastic-687-now-available-for-security.html