Open philhagen opened 4 years ago
also add for any entry with all necessary component fields
create ElasticSearch pipeline and apply via the logstash elasticsearch output
https://www.elastic.co/guide/en/logstash/current/plugins-outputs-elasticsearch.html
may be easier to just use a ruby implementation: https://github.com/rocknsm/rock-dashboards/blob/master/ecs-configuration/logstash/conf.d/logstash-900-filter-community_Id_hash-enrich.conf
See https://github.com/corelight/community-id-spec