logstash-plugins / logstash-patterns-core

Apache License 2.0
2.17k stars 980 forks source link

Feat: make BACULA_LOGLINE captures ECS compliant #295

Closed kares closed 3 years ago

kares commented 3 years ago

The bacula pattern set feels a bit unfinished, and making it 'more usable' got out-of-scope for now. However, there's a few tweaks (event on the legacy part) to at least pass sample logs used in tests...

Most of the matches use the bacula. namespace, there's no new captures (despite making sense on a few places).

kares commented 3 years ago

// cc @ebeahan @webmat not much ECS :cupid: here (mostly custom fields) - please take a look if you're able to spot anything