Skip to content

Commit

Permalink
Add event.ingested to Netflow module
Browse files Browse the repository at this point in the history
Add event.ingested to the pipeline in the Netflow Filebeat module.
  • Loading branch information
andrewkroh committed Nov 4, 2020
1 parent d2ea3c8 commit 4cd73e4
Show file tree
Hide file tree
Showing 2 changed files with 5 additions and 0 deletions.
1 change: 1 addition & 0 deletions CHANGELOG.next.asciidoc
Original file line number Diff line number Diff line change
Expand Up @@ -655,6 +655,7 @@ https://github.com/elastic/beats/compare/v7.0.0-alpha2...master[Check the HEAD d
- Update Okta documentation for new stateful restarts. {pull}22091[22091]
- Copy tag names from MISP data into events. {pull}21664[21664]
- Added TLS JA3 fingerprint, certificate not_before/not_after, certificate SHA1 hash, and certificate subject fields to Zeek SSL dataset. {pull}21696[21696]
- Added `event.ingested` field to data from the Netflow module. {pull}22412[22412]

*Heartbeat*

Expand Down
4 changes: 4 additions & 0 deletions x-pack/filebeat/module/netflow/log/ingest/pipeline.yml
Original file line number Diff line number Diff line change
Expand Up @@ -2,6 +2,10 @@
description: Pipeline for Filebeat NetFlow

processors:
- set:
field: event.ingested
value: '{{_ingest.timestamp}}'

# IP Geolocation Lookup
- geoip:
if: ctx.source?.geo == null
Expand Down

0 comments on commit 4cd73e4

Please sign in to comment.