You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
value: 'Processor {{{_ingest.on_failure_processor_type}}} with tag {{{_ingest.on_failure_processor_tag}}} in pipeline {{{_ingest.on_failure_pipeline}}} failed with message: {{{_ingest.on_failure_message}}}'
20
32
- set:
21
33
field: destination.address
22
34
copy_from: destination.ip
@@ -36,6 +48,18 @@ processors:
36
48
target_field: destination.mac
37
49
ignore_missing: true
38
50
51
+
- convert:
52
+
tag: convert_RemoteAddressIP4_ip
53
+
field: crowdstrike.RemoteAddressIP4
54
+
type: ip
55
+
ignore_missing: true
56
+
on_failure:
57
+
- remove:
58
+
field: crowdstrike.RemoteAddressIP4
59
+
ignore_missing: true
60
+
- append:
61
+
field: error.message
62
+
value: 'Processor {{{_ingest.on_failure_processor_type}}} with tag {{{_ingest.on_failure_processor_tag}}} in pipeline {{{_ingest.on_failure_pipeline}}} failed with message: {{{_ingest.on_failure_message}}}'
39
63
- rename:
40
64
field: crowdstrike.RemoteAddressIP4
41
65
target_field: source.ip
@@ -45,6 +69,13 @@ processors:
45
69
field: crowdstrike.RemoteAddressIP6
46
70
type: ip
47
71
ignore_missing: true
72
+
on_failure:
73
+
- remove:
74
+
field: crowdstrike.RemoteAddressIP6
75
+
ignore_missing: true
76
+
- append:
77
+
field: error.message
78
+
value: 'Processor {{{_ingest.on_failure_processor_type}}} with tag {{{_ingest.on_failure_processor_tag}}} in pipeline {{{_ingest.on_failure_pipeline}}} failed with message: {{{_ingest.on_failure_message}}}'
value: 'Processor {{{_ingest.on_failure_processor_type}}} with tag {{{_ingest.on_failure_processor_tag}}} in pipeline {{{_ingest.on_failure_pipeline}}} failed with message: {{{_ingest.on_failure_message}}}'
20
32
- set:
21
33
field: source.address
22
34
copy_from: source.ip
@@ -36,6 +48,18 @@ processors:
36
48
target_field: source.mac
37
49
ignore_missing: true
38
50
51
+
- convert:
52
+
tag: convert_RemoteAddressIP4_ip
53
+
field: crowdstrike.RemoteAddressIP4
54
+
type: ip
55
+
ignore_missing: true
56
+
on_failure:
57
+
- remove:
58
+
field: crowdstrike.RemoteAddressIP4
59
+
ignore_missing: true
60
+
- append:
61
+
field: error.message
62
+
value: 'Processor {{{_ingest.on_failure_processor_type}}} with tag {{{_ingest.on_failure_processor_tag}}} in pipeline {{{_ingest.on_failure_pipeline}}} failed with message: {{{_ingest.on_failure_message}}}'
39
63
- rename:
40
64
field: crowdstrike.RemoteAddressIP4
41
65
target_field: destination.ip
@@ -45,6 +69,13 @@ processors:
45
69
field: crowdstrike.RemoteAddressIP6
46
70
type: ip
47
71
ignore_missing: true
72
+
on_failure:
73
+
- remove:
74
+
field: crowdstrike.RemoteAddressIP6
75
+
ignore_missing: true
76
+
- append:
77
+
field: error.message
78
+
value: 'Processor {{{_ingest.on_failure_processor_type}}} with tag {{{_ingest.on_failure_processor_tag}}} in pipeline {{{_ingest.on_failure_pipeline}}} failed with message: {{{_ingest.on_failure_message}}}'
0 commit comments