你的浏览器禁用了JavaScript, 请开启后刷新浏览器获得更好的体验!
输入关键字进行搜索
搜索:
没有找到相关结果
gary - 入坑小菜
赞同来自:
processors: - decode_json_fields: fields: ['message'] process_array: true max_depth: 200 target: '' overwrite_keys: true - drop_fields: fields: ['message', 'ecs', 'beat', 'input_type', 'tags', 'count', '@version', 'log', 'offset', 'type', 'host'] - rename: fields: - from: "data.aws.sourceIPAddress" to: "@src_ip" ignore_missing: true fail_on_error: false when: regexp: data.aws.sourceIPAddress: \b\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3}\b - rename: fields: - from: "data.srcip" to: "@src_ip" ignore_missing: true fail_on_error: false when: regexp: data.srcip: \b\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3}\b - rename: fields: - from: "data.win.eventdata.ipAddress" to: "@src_ip" ignore_missing: true fail_on_error: false when: regexp: data.win.eventdata.ipAddress: \b\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3}\b
要回复问题请先登录或注册
入坑小菜
1 个回复
gary - 入坑小菜
赞同来自: