Skip to content

Commit 9241da8

Browse files
feature/qualys-was-13569
Adds original event tag if there is an error
1 parent fbe8418 commit 9241da8

File tree

1 file changed

+14
-9
lines changed
  • packages/qualys_was/data_stream/vulnerability/elasticsearch/ingest_pipeline

1 file changed

+14
-9
lines changed

packages/qualys_was/data_stream/vulnerability/elasticsearch/ingest_pipeline/default.yml

Lines changed: 14 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -4,7 +4,7 @@ processors:
44
- rename:
55
field: message
66
target_field: event.original
7-
if: 'ctx.event?.original == null'
7+
if: ctx.event?.original == null
88
description: 'Renames the original `message` field to `event.original` to store a copy of the original message.'
99
on_failure:
1010
- append:
@@ -13,7 +13,7 @@ processors:
1313
- remove:
1414
field: message
1515
ignore_missing: true
16-
if: 'ctx.event?.original != null'
16+
if: ctx.event?.original != null
1717
description: 'The `message` field is no longer required if the document has an `event.original` field.'
1818
- set:
1919
if: ctx['@timestamp'] != null
@@ -320,12 +320,17 @@ processors:
320320
tag: pipeline_knowledge_base
321321
ignore_missing_pipeline: true
322322
on_failure:
323-
- set:
323+
- append:
324+
field: error.message
325+
value: 'Processor {{{_ingest.on_failure_processor_type}}} with tag {{{_ingest.on_failure_processor_tag}}}
326+
in pipeline {{{_ingest.on_failure_pipeline}}} failed with message: {{{_ingest.on_failure_message}}}'
327+
- set:
324328
field: event.kind
325329
value: pipeline_error
326-
- append:
327-
field: error.message
328-
value: >-
329-
Processor '{{ _ingest.on_failure_processor_type }}'
330-
{{#_ingest.on_failure_processor_tag}}with tag '{{ _ingest.on_failure_processor_tag }}'
331-
{{/_ingest.on_failure_processor_tag}}failed with message '{{ _ingest.on_failure_message }}'
330+
tag: set_pipeline_error_to_event_kind
331+
if: ctx.error?.message != null
332+
- append:
333+
field: tags
334+
value: preserve_original_event
335+
allow_duplicates: false
336+
if: ctx.error?.message != null

0 commit comments

Comments
 (0)