forked from efi-k/winlogbeat2splunk
-
Notifications
You must be signed in to change notification settings - Fork 0
/
transforms.conf
73 lines (61 loc) · 1.58 KB
/
transforms.conf
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
#Beats
[ta-windows-fix-beats-xml-source]
DEST_KEY = MetaData:Source
REGEX = \"channel\"\:\"([^\"]*)
FORMAT = source::XmlWinEventLog:$1
[beats_eventdata_xml_block]
REGEX = (?ms)\"event_data\":{(.*?\")}\,
FORMAT = EventData_Xml::$1
[beats_system_props_xml_attributes_Name]
#Provider Name
SOURCE_KEY = _raw
REGEX = (?ms)\"provider\_name\":\"([^\"]*)
FORMAT = Name::$1
MV_ADD = 1
[beats_system_props_xml_attributes_Guid]
#Provider Guid
SOURCE_KEY = _raw
REGEX = (?ms)\"provider\_guid\":\"([^\"]*)
FORMAT = Guid::$1
MV_ADD = 1
[beats_system_props_xml_attributes_SystemTime]
#System Time
SOURCE_KEY = _raw
REGEX = (?ms)\"@timestamp\":\"([^\"]*)
FORMAT = SystemTime::$1
MV_ADD = 1
[beats_system_props_xml_attributes_RawTime]
#RawTime
SOURCE_KEY = _raw
REGEX = (?ms)\"created\":\"([^\"]*)
FORMAT = RawTime::$1
MV_ADD = 1
[beats_system_props_xml_attributes_ActivityID]
#ActivityID
SOURCE_KEY = _raw
REGEX = (?ms)\"activity_id\":\"([^\"]*)
FORMAT = ActivityID::$1
MV_ADD = 1
[beats_system_props_xml_attributes_ProcessID]
#ProcessID
SOURCE_KEY = _raw
REGEX = (?ms)\"process\":{\"thread\":{\"id\":\d*\}\,\"pid\"\:([^}]*)
FORMAT = ProcessID::$1
MV_ADD = 1
[beats_system_props_xml_attributes_ThreadID]
#ThreadID
SOURCE_KEY = _raw
REGEX = (?ms)\"process\":{\"thread\":{\"id\":([^}]*)
FORMAT = ThreadID::$1
MV_ADD = 1
[beats_eventdata_xml_data]
#Beats
REGEX = \"([^\"]*)\"\:\"([^\"]*)
FORMAT = $1::$2
MV_ADD = 1
[EventID_as_EventCode_beats]
REGEX = \"event\_id\"\:(?:\")?([^\"}\,]*)
FORMAT = EventCode::$1
[EventRecordID_as_RecordNumber_beats]
REGEX = \"record\_(?:id|number)\"\:([^\,\}\"]*)
FORMAT = RecordNumber::$1