Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add two migrated fields to ecs-migration.yml from #9645. #9878

Merged
merged 4 commits into from
Jan 7, 2019
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
39 changes: 25 additions & 14 deletions dev-tools/ecs-migration.yml
Original file line number Diff line number Diff line change
Expand Up @@ -54,6 +54,9 @@
alias6: true
alias: true


# Processor fields

# Docker processor
- from: docker.container.id
to: container.id
Expand All @@ -75,45 +78,38 @@
alias6: false
alias: true


# Filebeat modules

## Suricata module

# Processor fields

# Cloud
- form: meta.cloud.provider
- from: meta.cloud.provider
to: cloud.provider
alias: true
alias6: true

- form: meta.cloud.instance_id
- from: meta.cloud.instance_id
to: cloud.instance.id
alias: true
alias6: true

- form: meta.cloud.instance_name
- from: meta.cloud.instance_name
to: cloud.instance.name
alias: true
alias6: true

- form: meta.cloud.machine_type
- from: meta.cloud.machine_type
to: cloud.machine.type
alias: true
alias6: true

- form: meta.cloud.availability_zone
- from: meta.cloud.availability_zone
to: cloud.availability_zone
alias: true
alias6: true

- form: meta.cloud.project_id
- from: meta.cloud.project_id
to: cloud.project.id
alias: true
alias6: true

- form: meta.cloud.region
- from: meta.cloud.region
to: cloud.region
alias: true
alias6: true
Expand Down Expand Up @@ -591,13 +587,28 @@
to: http.version
alias: true


# Auditbeat

## From Auditbeat's auditd module.
- from: source.hostname
to: source.domain
alias: true


# Packetbeat

- from: http.request.body
to: http.request.body.content
alias6: false
alias: false

- from: http.response.body
to: http.response.body.content
alias6: false
alias: false


# Metricbeat

## Metricbeat base fields
Expand Down