You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Processor "{{{ _ingest.on_failure_processor_type }}}" with tag "{{{ _ingest.on_failure_processor_tag }}}" in pipeline "{{{ _ingest.on_failure_pipeline }}}" failed with message "{{{ _ingest.on_failure_message }}}"
Processor "{{{ _ingest.on_failure_processor_type }}}" with tag "{{{ _ingest.on_failure_processor_tag }}}" in pipeline "{{{ _ingest.on_failure_pipeline }}}" failed with message "{{{ _ingest.on_failure_message }}}"
Copy file name to clipboardExpand all lines: packages/cef/data_stream/log/elasticsearch/ingest_pipeline/fp-pipeline.yml
+9-2Lines changed: 9 additions & 2 deletions
Original file line number
Diff line number
Diff line change
@@ -3,29 +3,36 @@ description: Pipeline for Forcepoint CEF
3
3
processors:
4
4
# cs1 is ruleID
5
5
- set:
6
+
tag: set_rule_id_7a577460
6
7
field: rule.id
7
8
ignore_empty_value: true
8
9
value: '{{{cef.extensions.deviceCustomString1}}}'
9
10
# cs2 is natRuleID
10
11
- set:
12
+
tag: set_rule_id_c76c7491
11
13
field: rule.id
12
14
ignore_empty_value: true
13
15
value: '{{{cef.extensions.deviceCustomString2}}}'
14
16
# cs3 is VulnerabilityReference
15
17
- set:
18
+
tag: set_vulnerability_reference_0b703e9a
16
19
field: vulnerability.reference
17
20
ignore_empty_value: true
18
21
value: '{{{cef.extensions.deviceCustomString3}}}'
19
22
# cs4 is virusID
20
23
- set:
24
+
tag: set_cef_forcepoint_virus_id_ce0473c6
21
25
field: cef.forcepoint.virus_id
22
26
ignore_empty_value: true
23
27
value: '{{{cef.extensions.deviceCustomString4}}}'
24
28
on_failure:
25
29
- append:
26
30
field: error.message
27
-
value: |-
28
-
Processor "{{{ _ingest.on_failure_processor_type }}}" with tag "{{{ _ingest.on_failure_processor_tag }}}" in pipeline "{{{ _ingest.on_failure_pipeline }}}" failed with message "{{{ _ingest.on_failure_message }}}"
0 commit comments