Hi Jorest,
Please see below -
{
"filebeat-7.10.2-wazuh-alerts-pipeline": {
"description": "Wazuh alerts pipeline",
"processors": [
{
"json": {
"field": "message",
"add_to_root": true
}
},
{
"set": {
"override": false,
"ignore_failure": true,
"ignore_empty_value": true,
"field": "data.aws.region",
"value": "{{data.aws.awsRegion}}"
}
},
{
"set": {
"override": false,
"ignore_failure": true,
"ignore_empty_value": true,
"field": "data.aws.accountId",
"value": "{{data.aws.aws_account_id}}"
}
},
{
"geoip": {
"field": "data.srcip",
"target_field": "GeoLocation",
"properties": [
"city_name",
"country_name",
"region_name",
"location"
],
"ignore_missing": true,
"ignore_failure": true
}
},
{
"geoip": {
"ignore_missing": true,
"ignore_failure": true,
"field": "data.win.eventdata.ipAddress",
"target_field": "GeoLocation",
"properties": [
"city_name",
"country_name",
"region_name",
"location"
]
}
},
{
"geoip": {
"field": "data.aws.sourceIPAddress",
"target_field": "GeoLocation",
"properties": [
"city_name",
"country_name",
"region_name",
"location"
],
"ignore_missing": true,
"ignore_failure": true
}
},
{
"geoip": {
"target_field": "GeoLocation",
"properties": [
"city_name",
"country_name",
"region_name",
"location"
],
"ignore_missing": true,
"ignore_failure": true,
"field": "data.aws.client_ip"
}
},
{
"geoip": {
"ignore_missing": true,
"ignore_failure": true,
"field": "data.aws.service.action.networkConnectionAction.remoteIpDetails.ipAddressV4",
"target_field": "GeoLocation",
"properties": [
"city_name",
"country_name",
"region_name",
"location"
]
}
},
{
"geoip": {
"target_field": "GeoLocation",
"properties": [
"city_name",
"country_name",
"region_name",
"location"
],
"ignore_missing": true,
"ignore_failure": true,
"field": "data.aws.httpRequest.clientIp"
}
},
{
"geoip": {
"field": "data.gcp.jsonPayload.sourceIP",
"target_field": "GeoLocation",
"properties": [
"city_name",
"country_name",
"region_name",
"location"
],
"ignore_missing": true,
"ignore_failure": true
}
},
{
"geoip": {
"properties": [
"city_name",
"country_name",
"region_name",
"location"
],
"ignore_missing": true,
"ignore_failure": true,
"field": "data.office365.ClientIP",
"target_field": "GeoLocation"
}
},
{
"date": {
"field": "timestamp",
"target_field": "@timestamp",
"formats": [
"ISO8601"
],
"ignore_failure": false
}
},
{
"date_index_name": {
"ignore_failure": false,
"field": "timestamp",
"date_rounding": "d",
"index_name_prefix": "{{fields.index_prefix}}",
"index_name_format": "yyyy.MM.dd"
}
},
{
"remove": {
"field": "message",
"ignore_missing": true,
"ignore_failure": true
}
},
{
"remove": {
"field": "ecs",
"ignore_missing": true,
"ignore_failure": true
}
},
{
"remove": {
"ignore_failure": true,
"field": "beat",
"ignore_missing": true
}
},
{
"remove": {
"field": "input_type",
"ignore_missing": true,
"ignore_failure": true
}
},
{
"remove": {
"ignore_failure": true,
"field": "tags",
"ignore_missing": true
}
},
{
"remove": {
"ignore_missing": true,
"ignore_failure": true,
"field": "count"
}
},
{
"remove": {
"ignore_missing": true,
"ignore_failure": true,
"field": "@version"
}
},
{
"remove": {
"ignore_missing": true,
"ignore_failure": true,
"field": "log"
}
},
{
"remove": {
"field": "offset",
"ignore_missing": true,
"ignore_failure": true
}
},
{
"remove": {
"ignore_missing": true,
"ignore_failure": true,
"field": "type"
}
},
{
"remove": {
"field": "host",
"ignore_missing": true,
"ignore_failure": true
}
},
{
"remove": {
"field": "fields",
"ignore_missing": true,
"ignore_failure": true
}
},
{
"remove": {
"field": "event",
"ignore_missing": true,
"ignore_failure": true
}
},
{
"remove": {
"field": "fileset",
"ignore_missing": true,
"ignore_failure": true
}
},
{
"remove": {
"ignore_failure": true,
"field": "service",
"ignore_missing": true
}
}
],
"on_failure": [
{
"drop": {}
}
]
}
}