Skip to content

Commit c796820

Browse files
Add missing tag, formatting
1 parent 378f880 commit c796820

File tree

1 file changed

+3
-9
lines changed

1 file changed

+3
-9
lines changed

packages/cisco_secure_email_gateway/data_stream/log/elasticsearch/ingest_pipeline/pipeline_consolidated_event.yml

Lines changed: 3 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -7,15 +7,9 @@ processors:
77
- grok:
88
field: cisco_secure_email_gateway.log.message
99
patterns:
10-
- "^(?:%{DATA:_tmp.timestamp} )?\
11-
CEF:%{NUMBER:cisco_secure_email_gateway.log.cef_format_version}\
12-
\\|%{WORD:cisco_secure_email_gateway.log.appliance.vendor}\
13-
\\|%{DATA:cisco_secure_email_gateway.log.appliance.product}\
14-
\\|%{DATA:cisco_secure_email_gateway.log.appliance.version}\
15-
\\|%{DATA:cisco_secure_email_gateway.log.event_class_id}\
16-
\\|%{DATA:cisco_secure_email_gateway.log.event.name}\
17-
\\|%{WORD:event.severity}\
18-
\\|%{GREEDYDATA:_tmp.details}$"
10+
- "^(?:%{DATA:_tmp.timestamp} )?CEF:%{NUMBER:cisco_secure_email_gateway.log.cef_format_version}\\|%{WORD:cisco_secure_email_gateway.log.appliance.vendor}\\|%{DATA:cisco_secure_email_gateway.log.appliance.product}\\|%{DATA:cisco_secure_email_gateway.log.appliance.version}\\|%{DATA:cisco_secure_email_gateway.log.event_class_id}\\|%{DATA:cisco_secure_email_gateway.log.event.name}\\|%{WORD:event.severity}\\|%{GREEDYDATA:_tmp.details}$"
11+
tag: grok_be30f38e
12+
1913
- kv:
2014
field: _tmp.details
2115
target_field: _tmp.fields

0 commit comments

Comments
 (0)