Advertisement
Guest User

Untitled

a guest
Jul 20th, 2018
444
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.00 KB | None | 0 0
  1. #Remove metadata.
  2. [replace_event]
  3. LOOKAHEAD=100000000
  4. REGEX="Event":(.*)}$
  5. FORMAT=$1
  6. DEST_KEY=_raw
  7. SOURCE_KEY=_raw
  8.  
  9. [set_Host_value]
  10. REGEX = "host":"([a-zA-Z0-9-]{1,25})",
  11. FORMAT = host::$1
  12. SOURCE_KEY=_raw
  13. DEST_KEY = MetaData:Host
  14.  
  15. [set_Source_value]
  16. REGEX = "source":"([^\}\{,\"]*)",
  17. FORMAT = source::$1
  18. SOURCE_KEY=_raw
  19. DEST_KEY = MetaData:Source
  20.  
  21. [set_Index_value]
  22. REGEX = "index":"([a-zA-Z:_]*)",
  23. FORMAT = $1
  24. SOURCE_KEY=_raw
  25. DEST_KEY = _MetaData:Index
  26.  
  27. [set_SeverityID]
  28. REGEX = "SeverityID":([-0-9]{1,3}),
  29. FORMAT = SeverityID::$1
  30. SOURCE_KEY=_raw
  31. WRITE_META = true
  32.  
  33. [set_Component]
  34. REGEX = "Component":"([^\}\{,\"]*)",
  35. FORMAT = Component::$1
  36. SOURCE_KEY=_raw
  37. WRITE_META = true
  38.  
  39. [set_SessionID]
  40. REGEX = "SessionID":"([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12})",
  41. FORMAT = SessionID::$1
  42. SOURCE_KEY=_raw
  43. WRITE_META = true
  44.  
  45. [set_ComputerName]
  46. REGEX = "ComputerName":"([a-zA-Z0-9-]{1,25})",
  47. FORMAT = ComputerName::$1
  48. SOURCE_KEY=_raw
  49. WRITE_META=true
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement