Skip to content

Commit

Permalink
Add event.ingested to all rsa2elk modules (elastic#20714)
Browse files Browse the repository at this point in the history
Updated the autogenerated ingest pipelines to add the event.ingested
field.

Most pipelines already had the processor, just a few of them were
missing.

(cherry picked from commit 6636a8c)
  • Loading branch information
adriansr committed Aug 24, 2020
1 parent ea712b7 commit 00b3bd8
Show file tree
Hide file tree
Showing 16 changed files with 25 additions and 13 deletions.
2 changes: 1 addition & 1 deletion x-pack/filebeat/module/barracuda/waf/ingest/pipeline.yml
Original file line number Diff line number Diff line change
Expand Up @@ -2,10 +2,10 @@
description: Pipeline for Barracuda Web Application Firewall

processors:
# ECS event.ingested
- set:
field: event.ingested
value: '{{_ingest.timestamp}}'

# User agent
- user_agent:
field: user_agent.original
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -2,10 +2,10 @@
description: Pipeline for Blue Coat Director

processors:
# ECS event.ingested
- set:
field: event.ingested
value: '{{_ingest.timestamp}}'

# User agent
- user_agent:
field: user_agent.original
Expand Down
4 changes: 4 additions & 0 deletions x-pack/filebeat/module/cisco/nexus/ingest/pipeline.yml
Original file line number Diff line number Diff line change
Expand Up @@ -2,6 +2,10 @@
description: Pipeline for Cisco Nexus

processors:
# ECS event.ingested
- set:
field: event.ingested
value: '{{_ingest.timestamp}}'
# User agent
- user_agent:
field: user_agent.original
Expand Down
2 changes: 1 addition & 1 deletion x-pack/filebeat/module/cylance/protect/ingest/pipeline.yml
Original file line number Diff line number Diff line change
Expand Up @@ -2,10 +2,10 @@
description: Pipeline for CylanceProtect

processors:
# ECS event.ingested
- set:
field: event.ingested
value: '{{_ingest.timestamp}}'

# User agent
- user_agent:
field: user_agent.original
Expand Down
2 changes: 1 addition & 1 deletion x-pack/filebeat/module/f5/bigipapm/ingest/pipeline.yml
Original file line number Diff line number Diff line change
Expand Up @@ -2,10 +2,10 @@
description: Pipeline for Big-IP Access Policy Manager

processors:
# ECS event.ingested
- set:
field: event.ingested
value: '{{_ingest.timestamp}}'

# User agent
- user_agent:
field: user_agent.original
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -2,10 +2,10 @@
description: Pipeline for Fortinet FortiClient Endpoint Security

processors:
# ECS event.ingested
- set:
field: event.ingested
value: '{{_ingest.timestamp}}'

# User agent
- user_agent:
field: user_agent.original
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -2,10 +2,10 @@
description: Pipeline for Imperva SecureSphere

processors:
# ECS event.ingested
- set:
field: event.ingested
value: '{{_ingest.timestamp}}'

# User agent
- user_agent:
field: user_agent.original
Expand Down
2 changes: 1 addition & 1 deletion x-pack/filebeat/module/infoblox/nios/ingest/pipeline.yml
Original file line number Diff line number Diff line change
Expand Up @@ -2,10 +2,10 @@
description: Pipeline for Infoblox NIOS

processors:
# ECS event.ingested
- set:
field: event.ingested
value: '{{_ingest.timestamp}}'

# User agent
- user_agent:
field: user_agent.original
Expand Down
4 changes: 4 additions & 0 deletions x-pack/filebeat/module/juniper/junos/ingest/pipeline.yml
Original file line number Diff line number Diff line change
Expand Up @@ -2,6 +2,10 @@
description: Pipeline for Juniper JUNOS

processors:
# ECS event.ingested
- set:
field: event.ingested
value: '{{_ingest.timestamp}}'
# User agent
- user_agent:
field: user_agent.original
Expand Down
2 changes: 1 addition & 1 deletion x-pack/filebeat/module/microsoft/dhcp/ingest/pipeline.yml
Original file line number Diff line number Diff line change
Expand Up @@ -2,10 +2,10 @@
description: Pipeline for Microsoft DHCP

processors:
# ECS event.ingested
- set:
field: event.ingested
value: '{{_ingest.timestamp}}'

# User agent
- user_agent:
field: user_agent.original
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -2,10 +2,10 @@
description: Pipeline for Arbor Peakflow SP

processors:
# ECS event.ingested
- set:
field: event.ingested
value: '{{_ingest.timestamp}}'

# User agent
- user_agent:
field: user_agent.original
Expand Down
4 changes: 4 additions & 0 deletions x-pack/filebeat/module/radware/defensepro/ingest/pipeline.yml
Original file line number Diff line number Diff line change
Expand Up @@ -2,6 +2,10 @@
description: Pipeline for Radware DefensePro

processors:
# ECS event.ingested
- set:
field: event.ingested
value: '{{_ingest.timestamp}}'
# User agent
- user_agent:
field: user_agent.original
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -2,10 +2,10 @@
description: Pipeline for Sonicwall-FW

processors:
# ECS event.ingested
- set:
field: event.ingested
value: '{{_ingest.timestamp}}'

# User agent
- user_agent:
field: user_agent.original
Expand Down
2 changes: 1 addition & 1 deletion x-pack/filebeat/module/squid/log/ingest/pipeline.yml
Original file line number Diff line number Diff line change
Expand Up @@ -2,10 +2,10 @@
description: Pipeline for Squid

processors:
# ECS event.ingested
- set:
field: event.ingested
value: '{{_ingest.timestamp}}'

# User agent
- user_agent:
field: user_agent.original
Expand Down
2 changes: 1 addition & 1 deletion x-pack/filebeat/module/tomcat/log/ingest/pipeline.yml
Original file line number Diff line number Diff line change
Expand Up @@ -2,10 +2,10 @@
description: Pipeline for Apache Tomcat

processors:
# ECS event.ingested
- set:
field: event.ingested
value: '{{_ingest.timestamp}}'

# User agent
- user_agent:
field: user_agent.original
Expand Down
2 changes: 1 addition & 1 deletion x-pack/filebeat/module/zscaler/zia/ingest/pipeline.yml
Original file line number Diff line number Diff line change
Expand Up @@ -2,10 +2,10 @@
description: Pipeline for Zscaler NSS

processors:
# ECS event.ingested
- set:
field: event.ingested
value: '{{_ingest.timestamp}}'

# User agent
- user_agent:
field: user_agent.original
Expand Down

0 comments on commit 00b3bd8

Please sign in to comment.