Skip to content

Commit 865226a

Browse files
authored
Merge pull request #39 from mkubenka/fix/logstash-5.x
Fix Logstash 5.x
2 parents 7a6e498 + cb985d8 commit 865226a

File tree

2 files changed

+5
-3
lines changed

2 files changed

+5
-3
lines changed

2081_filter_section_h_convert_to_key-value.conf

Lines changed: 4 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -21,18 +21,20 @@ filter {
2121
ruby {
2222
code => "
2323
auditLogTrailer = event.get('auditLogTrailer').to_hash
24-
auditLogTrailerMessages = event.get('auditLogTrailerMessages').to_hash
24+
auditLogTrailerMessages = event.get('auditLogTrailerMessages')
2525
auditLogTrailer.each { |k, v|
2626
if !v.nil? and v.is_a? String
2727
auditLogTrailer[k] = v.strip
2828
end
2929
}
3030
auditLogTrailer.delete('Message')
3131
auditLogTrailer['messages'] = auditLogTrailerMessages
32+
33+
event.set('auditLogTrailer', auditLogTrailer)
3234
"
3335
}
3436

35-
drop {
37+
mutate {
3638
remove_field => ['auditLogTrailerMessages']
3739
}
3840
}

2089_filter_section_h_example_severities.conf

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -11,7 +11,7 @@ filter {
1111
ruby {
1212
code => "
1313
modsecSeverities = Set.new
14-
trailerMsgs = event.get('auditLogTrailerMessages').to_hash
14+
trailerMsgs = event.get('auditLogTrailer[messages]')
1515
trailerMsgs.each {|m|
1616
if m.key?('severity')
1717
modsecSeverities.add(m['severity'])

0 commit comments

Comments
 (0)