Skip to content

Commit 9bf3ba2

Browse files
committed
reposition drop processor
1 parent df20fa8 commit 9bf3ba2

File tree

17 files changed

+47
-47
lines changed

17 files changed

+47
-47
lines changed

packages/ti_google_threat_intelligence/_dev/build/docs/README.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -120,7 +120,7 @@ Detection Rules match the user's Elastic environment data with GTI data, generat
120120
2. Search for **Google Threat Intelligence** to find prebuilt Elastic detection rules.
121121
3. Four detection rules are available for **IP, URL, File, and Domain**. Users can install one or more rules as needed.
122122

123-
To tailor a rule based on elastic Environment:
123+
To tailor a rule based on Elastic environment:
124124

125125
1. Click the three dots on the right side of any detection rule.
126126
2. Select **Duplicate Rule**.

packages/ti_google_threat_intelligence/data_stream/cryptominer/elasticsearch/ingest_pipeline/default.yml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,9 @@
11
---
22
description: Pipeline for processing Cryptominer events.
33
processors:
4+
- drop:
5+
if: ctx.message == 'retry'
6+
tag: drop_retry_events
47
- set:
58
field: ecs.version
69
tag: set_ecs_version
@@ -9,9 +12,6 @@ processors:
912
tag: data_collection_error
1013
if: ctx.error?.message != null && ctx.message == null && ctx.event?.original == null
1114
description: error message set and no data to process.
12-
- drop:
13-
if: ctx.message == 'retry'
14-
tag: drop_retry_events
1515
- remove:
1616
field:
1717
- organization

packages/ti_google_threat_intelligence/data_stream/first_stage_delivery_vectors/elasticsearch/ingest_pipeline/default.yml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,9 @@
11
---
22
description: Pipeline for processing First Stage Delivery Vectors events.
33
processors:
4+
- drop:
5+
if: ctx.message == 'retry'
6+
tag: drop_retry_events
47
- set:
58
field: ecs.version
69
tag: set_ecs_version
@@ -9,9 +12,6 @@ processors:
912
tag: data_collection_error
1013
if: ctx.error?.message != null && ctx.message == null && ctx.event?.original == null
1114
description: error message set and no data to process.
12-
- drop:
13-
if: ctx.message == 'retry'
14-
tag: drop_retry_events
1515
- remove:
1616
field:
1717
- organization

packages/ti_google_threat_intelligence/data_stream/infostealer/elasticsearch/ingest_pipeline/default.yml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,9 @@
11
---
22
description: Pipeline for processing Infostealer events.
33
processors:
4+
- drop:
5+
if: ctx.message == 'retry'
6+
tag: drop_retry_events
47
- set:
58
field: ecs.version
69
tag: set_ecs_version
@@ -9,9 +12,6 @@ processors:
912
tag: data_collection_error
1013
if: ctx.error?.message != null && ctx.message == null && ctx.event?.original == null
1114
description: error message set and no data to process.
12-
- drop:
13-
if: ctx.message == 'retry'
14-
tag: drop_retry_events
1515
- remove:
1616
field:
1717
- organization

packages/ti_google_threat_intelligence/data_stream/ioc_stream/elasticsearch/ingest_pipeline/default.yml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,9 @@
11
---
22
description: Pipeline for processing ioc_stream logs.
33
processors:
4+
- drop:
5+
if: ctx.message == 'retry'
6+
tag: drop_retry_events
47
- set:
58
field: ecs.version
69
tag: set_ecs_version
@@ -9,9 +12,6 @@ processors:
912
tag: data_collection_error
1013
if: ctx.error?.message != null && ctx.message == null && ctx.event?.original == null
1114
description: error message set and no data to process.
12-
- drop:
13-
if: ctx.message == 'retry'
14-
tag: drop_retry_events
1515
- remove:
1616
field:
1717
- organization

packages/ti_google_threat_intelligence/data_stream/iot/elasticsearch/ingest_pipeline/default.yml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,9 @@
11
---
22
description: Pipeline for processing IOT events.
33
processors:
4+
- drop:
5+
if: ctx.message == 'retry'
6+
tag: drop_retry_events
47
- set:
58
field: ecs.version
69
tag: set_ecs_version
@@ -9,9 +12,6 @@ processors:
912
tag: data_collection_error
1013
if: ctx.error?.message != null && ctx.message == null && ctx.event?.original == null
1114
description: error message set and no data to process.
12-
- drop:
13-
if: ctx.message == 'retry'
14-
tag: drop_retry_events
1515
- remove:
1616
field:
1717
- organization

packages/ti_google_threat_intelligence/data_stream/linux/elasticsearch/ingest_pipeline/default.yml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,9 @@
11
---
22
description: Pipeline for processing Linux events.
33
processors:
4+
- drop:
5+
if: ctx.message == 'retry'
6+
tag: drop_retry_events
47
- set:
58
field: ecs.version
69
tag: set_ecs_version
@@ -9,9 +12,6 @@ processors:
912
tag: data_collection_error
1013
if: ctx.error?.message != null && ctx.message == null && ctx.event?.original == null
1114
description: error message set and no data to process.
12-
- drop:
13-
if: ctx.message == 'retry'
14-
tag: drop_retry_events
1515
- remove:
1616
field:
1717
- organization

packages/ti_google_threat_intelligence/data_stream/malicious_network_infrastructure/elasticsearch/ingest_pipeline/default.yml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,9 @@
11
---
22
description: Pipeline for processing Malicious Network Infrastructure events.
33
processors:
4+
- drop:
5+
if: ctx.message == 'retry'
6+
tag: drop_retry_events
47
- set:
58
field: ecs.version
69
tag: set_ecs_version
@@ -9,9 +12,6 @@ processors:
912
tag: data_collection_error
1013
if: ctx.error?.message != null && ctx.message == null && ctx.event?.original == null
1114
description: error message set and no data to process.
12-
- drop:
13-
if: ctx.message == 'retry'
14-
tag: drop_retry_events
1515
- remove:
1616
field:
1717
- organization

packages/ti_google_threat_intelligence/data_stream/malware/elasticsearch/ingest_pipeline/default.yml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,9 @@
11
---
22
description: Pipeline for processing Malware events.
33
processors:
4+
- drop:
5+
if: ctx.message == 'retry'
6+
tag: drop_retry_events
47
- set:
58
field: ecs.version
69
tag: set_ecs_version
@@ -9,9 +12,6 @@ processors:
912
tag: data_collection_error
1013
if: ctx.error?.message != null && ctx.message == null && ctx.event?.original == null
1114
description: error message set and no data to process.
12-
- drop:
13-
if: ctx.message == 'retry'
14-
tag: drop_retry_events
1515
- remove:
1616
field:
1717
- organization

packages/ti_google_threat_intelligence/data_stream/mobile/elasticsearch/ingest_pipeline/default.yml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,9 @@
11
---
22
description: Pipeline for processing Mobile events.
33
processors:
4+
- drop:
5+
if: ctx.message == 'retry'
6+
tag: drop_retry_events
47
- set:
58
field: ecs.version
69
tag: set_ecs_version
@@ -9,9 +12,6 @@ processors:
912
tag: data_collection_error
1013
if: ctx.error?.message != null && ctx.message == null && ctx.event?.original == null
1114
description: error message set and no data to process.
12-
- drop:
13-
if: ctx.message == 'retry'
14-
tag: drop_retry_events
1515
- remove:
1616
field:
1717
- organization

0 commit comments

Comments
 (0)