From 8db525573e5e4feaa0ea4c9cf2ce336926e7edbe Mon Sep 17 00:00:00 2001 From: beats-jenkins Date: Thu, 1 Nov 2018 11:22:34 +0100 Subject: [PATCH] Migrate fileset to ECS The following fields were migrated to ECS: * fileset.name -> event.dataset * fileset.module -> event.module Changes: * Update generated files * Update tests * Update changelog * Update migration file --- CHANGELOG.asciidoc | 2 + dev-tools/ecs-migration.yml | 18 ++- filebeat/_meta/fields.common.yml | 8 -- filebeat/channel/factory.go | 4 +- filebeat/docs/fields.asciidoc | 16 --- filebeat/include/fields.go | 2 +- .../access/test/test.log-expected.json | 16 +-- .../apache2/error/test/test.log-expected.json | 12 +- .../auditd/log/test/test.log-expected.json | 8 +- .../audit/test/test.log-expected.json | 28 ++-- .../gc/test/test.log-expected.json | 12 +- .../server/test/test.log-expected.json | 76 +++++----- .../slowlog/test/test.log-expected.json | 24 ++-- .../log/test/default.log-expected.json | 4 +- .../log/test/haproxy.log-expected.json | 4 +- .../haproxy/log/test/tcplog.log-expected.json | 4 +- .../icinga/debug/test/test.log-expected.json | 12 +- .../icinga/main/test/test.log-expected.json | 12 +- .../startup/test/test.log-expected.json | 12 +- .../iis/access/test/test.log-expected.json | 12 +- .../iis/error/test/test.log-expected.json | 16 +-- .../log/test/controller.log-expected.json | 80 +++++------ .../kafka/log/test/server.log-expected.json | 80 +++++------ .../test/state-change-1.1.0.log-expected.json | 4 +- .../test/state-change-2.0.0.log-expected.json | 4 +- .../log/test/state-change.log-expected.json | 4 +- .../kibana/log/test/test.log-expected.json | 12 +- .../log/test/logstash-plain.log-expected.json | 8 +- .../test/slowlog-plain.log-expected.json | 4 +- .../mongodb-debian-3.2.11.log-expected.json | 136 +++++++++--------- .../nginx/access/test/test.log-expected.json | 28 ++-- .../nginx/error/test/error.log-expected.json | 8 +- .../result/test/test.log-expected.json | 4 +- ...-9.6-debian-with-slowlog.log-expected.json | 72 +++++----- .../redis/log/test/test.log-expected.json | 16 +-- .../system/auth/test/test.log-expected.json | 40 +++--- .../darwin-syslog-sample.log-expected.json | 12 +- .../access/test/test.log-expected.json | 8 +- filebeat/tests/system/test_modules.py | 6 +- .../eve/test/eve-alerts.log-expected.json | 80 +++++------ .../eve/test/eve-small.log-expected.json | 32 ++--- 41 files changed, 464 insertions(+), 476 deletions(-) diff --git a/CHANGELOG.asciidoc b/CHANGELOG.asciidoc index d386e4abdc8..9ebc41bb933 100644 --- a/CHANGELOG.asciidoc +++ b/CHANGELOG.asciidoc @@ -20,6 +20,8 @@ https://github.com/elastic/beats/compare/v6.4.0...master[Check the HEAD diff] - Use `initial_scan` action for new paths. {pull}7954[7954] *Filebeat* +- Rename `fileset.name` to `event.name`. +- Rename `fileset.module` to `event.module`. - Remove the deprecated `prospector(s)` option in the configuration use `input(s)` instead. {pull}8909[8909] - Rename `offset` to `log.offset`. diff --git a/dev-tools/ecs-migration.yml b/dev-tools/ecs-migration.yml index 96b8af0993f..10a2642bda4 100644 --- a/dev-tools/ecs-migration.yml +++ b/dev-tools/ecs-migration.yml @@ -11,7 +11,17 @@ # # Copy to is useful for fields where multiple fields map to the same ECS field # copy_to: true-if-field-should-be-copied-to-target-in-6x - - from: offset - to: log.offset - alias: true - copy_to: false +- from: offset + to: log.offset + alias: true + copy_to: false + +- from: fileset.name + to: event.dataset + alias: true + copy_to: false + +- from: fileset.module + to: event.module + alias: true + copy_to: false diff --git a/filebeat/_meta/fields.common.yml b/filebeat/_meta/fields.common.yml index 9aae73bce53..014fb16627c 100644 --- a/filebeat/_meta/fields.common.yml +++ b/filebeat/_meta/fields.common.yml @@ -41,14 +41,6 @@ the original `@timestamp` (representing the time when the log line was read) in this field. - - name: fileset.module - description: > - The Filebeat module that generated this event. - - - name: fileset.name - description: > - The Filebeat fileset that generated this event. - - name: syslog.facility type: long required: false diff --git a/filebeat/channel/factory.go b/filebeat/channel/factory.go index 5222ccba826..99399d20e0d 100644 --- a/filebeat/channel/factory.go +++ b/filebeat/channel/factory.go @@ -103,10 +103,10 @@ func (f *OutletFactory) Create(p beat.Pipeline, cfg *common.Config, dynFields *c fields := common.MapStr{} setMeta(fields, "module", config.Module) - setMeta(fields, "name", config.Fileset) + setMeta(fields, "dataset", config.Fileset) if len(fields) > 0 { fields = common.MapStr{ - "fileset": fields, + "event": fields, } } if config.Type != "" { diff --git a/filebeat/docs/fields.asciidoc b/filebeat/docs/fields.asciidoc index 5e160063f06..7705c3128fa 100644 --- a/filebeat/docs/fields.asciidoc +++ b/filebeat/docs/fields.asciidoc @@ -4687,22 +4687,6 @@ The input type from which the event was generated. This field is set to the valu In case the ingest pipeline parses the timestamp from the log contents, it stores the original `@timestamp` (representing the time when the log line was read) in this field. --- - -*`fileset.module`*:: -+ --- -The Filebeat module that generated this event. - - --- - -*`fileset.name`*:: -+ --- -The Filebeat fileset that generated this event. - - -- *`syslog.facility`*:: diff --git a/filebeat/include/fields.go b/filebeat/include/fields.go index c1d1bd9ca12..aae7d974d68 100644 --- a/filebeat/include/fields.go +++ b/filebeat/include/fields.go @@ -31,5 +31,5 @@ func init() { // Asset returns asset data func Asset() string { - return "" + return "" } diff --git a/filebeat/module/apache2/access/test/test.log-expected.json b/filebeat/module/apache2/access/test/test.log-expected.json index ad39e1af00b..e9a306b0930 100644 --- a/filebeat/module/apache2/access/test/test.log-expected.json +++ b/filebeat/module/apache2/access/test/test.log-expected.json @@ -8,8 +8,8 @@ "apache2.access.response_code": "404", "apache2.access.url": "/favicon.ico", "apache2.access.user_name": "-", - "fileset.module": "apache2", - "fileset.name": "access", + "event.dataset": "access", + "event.module": "apache2", "input.type": "log", "log.offset": 0 }, @@ -32,8 +32,8 @@ "apache2.access.user_agent.os_minor": "12", "apache2.access.user_agent.os_name": "Mac OS X", "apache2.access.user_name": "-", - "fileset.module": "apache2", - "fileset.name": "access", + "event.dataset": "access", + "event.module": "apache2", "input.type": "log", "log.offset": 73 }, @@ -42,8 +42,8 @@ "apache2.access.remote_ip": "::1", "apache2.access.response_code": "408", "apache2.access.user_name": "-", - "fileset.module": "apache2", - "fileset.name": "access", + "event.dataset": "access", + "event.module": "apache2", "input.type": "log", "log.offset": 238 }, @@ -65,8 +65,8 @@ "apache2.access.user_agent.os_name": "Windows 7", "apache2.access.user_agent.patch": "a2", "apache2.access.user_name": "-", - "fileset.module": "apache2", - "fileset.name": "access", + "event.dataset": "access", + "event.module": "apache2", "input.type": "log", "log.offset": 285 } diff --git a/filebeat/module/apache2/error/test/test.log-expected.json b/filebeat/module/apache2/error/test/test.log-expected.json index 42cfe8441f9..3832540823f 100644 --- a/filebeat/module/apache2/error/test/test.log-expected.json +++ b/filebeat/module/apache2/error/test/test.log-expected.json @@ -4,8 +4,8 @@ "apache2.error.client": "192.168.33.1", "apache2.error.level": "error", "apache2.error.message": "File does not exist: /var/www/favicon.ico", - "fileset.module": "apache2", - "fileset.name": "error", + "event.dataset": "error", + "event.module": "apache2", "input.type": "log", "log.offset": 0 }, @@ -15,8 +15,8 @@ "apache2.error.message": "AH00094: Command line: '/usr/local/Cellar/httpd24/2.4.23_2/bin/httpd'", "apache2.error.module": "core", "apache2.error.pid": "11379", - "fileset.module": "apache2", - "fileset.name": "error", + "event.dataset": "error", + "event.module": "apache2", "input.type": "log", "log.offset": 99 }, @@ -28,8 +28,8 @@ "apache2.error.module": "core", "apache2.error.pid": "35708", "apache2.error.tid": "4328636416", - "fileset.module": "apache2", - "fileset.name": "error", + "event.dataset": "error", + "event.module": "apache2", "input.type": "log", "log.offset": 229 } diff --git a/filebeat/module/auditd/log/test/test.log-expected.json b/filebeat/module/auditd/log/test/test.log-expected.json index bb874d7b82a..952d4ed5cea 100644 --- a/filebeat/module/auditd/log/test/test.log-expected.json +++ b/filebeat/module/auditd/log/test/test.log-expected.json @@ -11,8 +11,8 @@ "auditd.log.ses": "4294967295", "auditd.log.src": "192.168.2.0", "auditd.log.src_prefixlen": "24", - "fileset.module": "auditd", - "fileset.name": "log", + "event.dataset": "log", + "event.module": "auditd", "input.type": "log", "log.offset": 0 }, @@ -44,8 +44,8 @@ "auditd.log.syscall": "44", "auditd.log.tty": "(none)", "auditd.log.uid": "0", - "fileset.module": "auditd", - "fileset.name": "log", + "event.dataset": "log", + "event.module": "auditd", "input.type": "log", "log.offset": 174 } diff --git a/filebeat/module/elasticsearch/audit/test/test.log-expected.json b/filebeat/module/elasticsearch/audit/test/test.log-expected.json index 4bfa83c31ea..4e239b6a7d7 100644 --- a/filebeat/module/elasticsearch/audit/test/test.log-expected.json +++ b/filebeat/module/elasticsearch/audit/test/test.log-expected.json @@ -6,8 +6,8 @@ "elasticsearch.audit.origin_address": "147.107.128.77", "elasticsearch.audit.principal": "i030648", "elasticsearch.audit.uri": "/_xpack/security/_authenticate", - "fileset.module": "elasticsearch", - "fileset.name": "audit", + "event.dataset": "audit", + "event.module": "elasticsearch", "input.type": "log", "log.offset": 0, "message": "[2018-06-19T05:16:15,549] [rest] [authentication_failed] origin_address=[147.107.128.77], principal=[i030648], uri=[/_xpack/security/_authenticate]", @@ -21,8 +21,8 @@ "elasticsearch.audit.principal": "rado", "elasticsearch.audit.uri": "/_xpack/security/_authenticate", "elasticsearch.node.name": "v_VJhjV", - "fileset.module": "elasticsearch", - "fileset.name": "audit", + "event.dataset": "audit", + "event.module": "elasticsearch", "input.type": "log", "log.offset": 155, "message": "[2018-06-19T05:07:52,304] [v_VJhjV] [rest] [authentication_failed]\torigin_address=[172.22.0.3], principal=[rado], uri=[/_xpack/security/_authenticate]", @@ -37,8 +37,8 @@ "elasticsearch.audit.origin_type": "local_node", "elasticsearch.audit.principal": "_xpack_security", "elasticsearch.audit.request": "ClearScrollRequest", - "fileset.module": "elasticsearch", - "fileset.name": "audit", + "event.dataset": "audit", + "event.module": "elasticsearch", "input.type": "log", "log.offset": 306, "message": "[2018-06-19T05:00:15,778] [transport] [access_granted] origin_type=[local_node], origin_address=[192.168.1.165], principal=[_xpack_security], action=[indices:data/read/scroll/clear], request=[ClearScrollRequest]", @@ -51,8 +51,8 @@ "elasticsearch.audit.origin_address": "172.22.0.3", "elasticsearch.audit.uri": "/_xpack/security/_authenticate", "elasticsearch.node.name": "v_VJhjV", - "fileset.module": "elasticsearch", - "fileset.name": "audit", + "event.dataset": "audit", + "event.module": "elasticsearch", "input.type": "log", "log.offset": 519, "message": "[2018-06-19T05:07:45,544] [v_VJhjV] [rest] [anonymous_access_denied]\torigin_address=[172.22.0.3], uri=[/_xpack/security/_authenticate]", @@ -65,8 +65,8 @@ "elasticsearch.audit.origin_address": "147.107.128.77", "elasticsearch.audit.principal": "N078801", "elasticsearch.audit.uri": "/_xpack/security/_authenticate", - "fileset.module": "elasticsearch", - "fileset.name": "audit", + "event.dataset": "audit", + "event.module": "elasticsearch", "input.type": "log", "log.offset": 654, "message": "[2018-06-19T05:26:27,268] [rest] [authentication_failed]\torigin_address=[147.107.128.77], principal=[N078801], uri=[/_xpack/security/_authenticate]", @@ -81,8 +81,8 @@ "elasticsearch.audit.origin_type": "rest", "elasticsearch.audit.principal": "_anonymous", "elasticsearch.audit.request": "MainRequest", - "fileset.module": "elasticsearch", - "fileset.name": "audit", + "event.dataset": "audit", + "event.module": "elasticsearch", "input.type": "log", "log.offset": 802, "message": "[2018-06-19T05:55:26,898] [transport] [access_denied]\torigin_type=[rest], origin_address=[147.107.128.77], principal=[_anonymous], action=[cluster:monitor/main], request=[MainRequest]", @@ -97,8 +97,8 @@ "elasticsearch.audit.request_body": "body", "elasticsearch.audit.uri": "/_nodes?filter_path=nodes.*.version%2Cnodes.*.http.publish_address%2Cnodes.*.ip", "elasticsearch.node.name": "v_VJhjV", - "fileset.module": "elasticsearch", - "fileset.name": "audit", + "event.dataset": "audit", + "event.module": "elasticsearch", "input.type": "log", "log.offset": 986, "message": "[2018-06-19T05:24:15,190] [v_VJhjV] [rest] [authentication_failed]\torigin_address=[172.18.0.3], principal=[elastic], uri=[/_nodes?filter_path=nodes.*.version%2Cnodes.*.http.publish_address%2Cnodes.*.ip], request_body=[body]", diff --git a/filebeat/module/elasticsearch/gc/test/test.log-expected.json b/filebeat/module/elasticsearch/gc/test/test.log-expected.json index beae001398a..87a1e80be98 100644 --- a/filebeat/module/elasticsearch/gc/test/test.log-expected.json +++ b/filebeat/module/elasticsearch/gc/test/test.log-expected.json @@ -11,8 +11,8 @@ "elasticsearch.gc.phase.cpu_time.user_sec": "0.01", "elasticsearch.gc.phase.duration_sec": "0.0021716", "elasticsearch.gc.phase.name": "CMS Initial Mark", - "fileset.module": "elasticsearch", - "fileset.name": "gc", + "event.dataset": "gc", + "event.module": "elasticsearch", "input.type": "log", "log.offset": 0, "message": "2018-03-03T19:37:06.157+0500: 14597.826: [GC (CMS Initial Mark) [1 CMS-initial-mark: 131804K(174784K)] 142444K(253440K), 0.0021716 secs] [Times: user=0.01 sys=0.00, real=0.00 secs]", @@ -23,8 +23,8 @@ "elasticsearch.gc.jvm_runtime_sec": "1396138.752", "elasticsearch.gc.stopping_threads_time_sec": "0.0000702", "elasticsearch.gc.threads_total_stop_time_sec": "0.0083760", - "fileset.module": "elasticsearch", - "fileset.name": "gc", + "event.dataset": "gc", + "event.module": "elasticsearch", "input.type": "log", "log.offset": 181, "message": "2018-06-11T01:53:11.382+0000: 1396138.752: Total time for which application threads were stopped: 0.0083760 seconds, Stopping threads took: 0.0000702 seconds", @@ -49,8 +49,8 @@ "elasticsearch.gc.phase.weak_refs_processing_time_sec": "0.0003647", "elasticsearch.gc.young_gen.size_kb": "157248", "elasticsearch.gc.young_gen.used_kb": "113198", - "fileset.module": "elasticsearch", - "fileset.name": "gc", + "event.dataset": "gc", + "event.module": "elasticsearch", "input.type": "log", "log.offset": 339, "message": "2018-06-30T16:35:26.632+0500: 224.671: [GC (CMS Final Remark) [YG occupancy: 113198 K (157248 K)]224.671: [Rescan (parallel) , 0.0148273 secs]224.686: [weak refs processing, 0.0003647 secs]224.687: [class unloading, 0.0188407 secs]224.705: [scrub symbol table, 0.0100207 secs]224.715: [scrub string table, 0.0005253 secs][1 CMS-remark: 277821K(349568K)] 391020K(506816K), 0.0457689 secs] [Times: user=0.12 sys=0.00, real=0.04 secs]", diff --git a/filebeat/module/elasticsearch/server/test/test.log-expected.json b/filebeat/module/elasticsearch/server/test/test.log-expected.json index 7eacc62cf02..60fbf0c1a2c 100644 --- a/filebeat/module/elasticsearch/server/test/test.log-expected.json +++ b/filebeat/module/elasticsearch/server/test/test.log-expected.json @@ -4,8 +4,8 @@ "elasticsearch.index.name": "test-filebeat-modules", "elasticsearch.node.name": "vWNJsZ3", "elasticsearch.server.component": "o.e.c.m.MetaDataCreateIndexService", - "fileset.module": "elasticsearch", - "fileset.name": "server", + "event.dataset": "server", + "event.module": "elasticsearch", "input.type": "log", "log.level": "INFO", "log.offset": 0, @@ -16,8 +16,8 @@ "@timestamp": "2018-05-17T08:19:35,939", "elasticsearch.node.name": "", "elasticsearch.server.component": "o.e.n.Node", - "fileset.module": "elasticsearch", - "fileset.name": "server", + "event.dataset": "server", + "event.module": "elasticsearch", "input.type": "log", "log.level": "INFO", "log.offset": 209, @@ -28,8 +28,8 @@ "@timestamp": "2018-05-17T08:19:36,089", "elasticsearch.node.name": "vWNJsZ3", "elasticsearch.server.component": "o.e.e.NodeEnvironment", - "fileset.module": "elasticsearch", - "fileset.name": "server", + "event.dataset": "server", + "event.module": "elasticsearch", "input.type": "log", "log.level": "INFO", "log.offset": 289, @@ -40,8 +40,8 @@ "@timestamp": "2018-05-17T08:19:36,090", "elasticsearch.node.name": "vWNJsZ3", "elasticsearch.server.component": "o.e.e.NodeEnvironment", - "fileset.module": "elasticsearch", - "fileset.name": "server", + "event.dataset": "server", + "event.module": "elasticsearch", "input.type": "log", "log.level": "INFO", "log.offset": 477, @@ -51,8 +51,8 @@ { "@timestamp": "2018-05-17T08:19:36,116", "elasticsearch.server.component": "o.e.n.Node", - "fileset.module": "elasticsearch", - "fileset.name": "server", + "event.dataset": "server", + "event.module": "elasticsearch", "input.type": "log", "log.level": "INFO", "log.offset": 611, @@ -63,8 +63,8 @@ "@timestamp": "2018-05-17T08:23:48,941", "elasticsearch.node.name": "vWNJsZ3", "elasticsearch.server.component": "o.e.c.r.a.DiskThresholdMonitor", - "fileset.module": "elasticsearch", - "fileset.name": "server", + "event.dataset": "server", + "event.module": "elasticsearch", "input.type": "log", "log.level": "INFO", "log.offset": 766, @@ -76,8 +76,8 @@ "elasticsearch.index.name": "filebeat-test-input", "elasticsearch.node.name": "vWNJsZ3", "elasticsearch.server.component": "o.e.c.m.MetaDataCreateIndexService", - "fileset.module": "elasticsearch", - "fileset.name": "server", + "event.dataset": "server", + "event.module": "elasticsearch", "input.type": "log", "log.level": "INFO", "log.offset": 1034, @@ -90,8 +90,8 @@ "elasticsearch.index.name": "filebeat-test-input", "elasticsearch.node.name": "vWNJsZ3", "elasticsearch.server.component": "o.e.c.m.MetaDataMappingService", - "fileset.module": "elasticsearch", - "fileset.name": "server", + "event.dataset": "server", + "event.module": "elasticsearch", "input.type": "log", "log.level": "INFO", "log.offset": 1239, @@ -104,8 +104,8 @@ "elasticsearch.index.name": ".kibana", "elasticsearch.node.name": "QGY1F5P", "elasticsearch.server.component": "o.e.c.m.MetaDataMappingService", - "fileset.module": "elasticsearch", - "fileset.name": "server", + "event.dataset": "server", + "event.module": "elasticsearch", "input.type": "log", "log.level": "INFO", "log.offset": 1380, @@ -116,8 +116,8 @@ "@timestamp": "2018-05-17T08:29:25,598", "elasticsearch.node.name": "vWNJsZ3", "elasticsearch.server.component": "o.e.n.Node", - "fileset.module": "elasticsearch", - "fileset.name": "server", + "event.dataset": "server", + "event.module": "elasticsearch", "input.type": "log", "log.level": "INFO", "log.offset": 1509, @@ -128,8 +128,8 @@ "@timestamp": "2018-05-17T08:29:25,612", "elasticsearch.node.name": "vWNJsZ3", "elasticsearch.server.component": "o.e.n.Node", - "fileset.module": "elasticsearch", - "fileset.name": "server", + "event.dataset": "server", + "event.module": "elasticsearch", "input.type": "log", "log.level": "INFO", "log.offset": 1591, @@ -140,8 +140,8 @@ "@timestamp": "2018-07-03T11:45:48,548", "elasticsearch.node.name": "srvmulpvlsk252_md", "elasticsearch.server.component": "o.e.d.z.ZenDiscovery", - "fileset.module": "elasticsearch", - "fileset.name": "server", + "event.dataset": "server", + "event.module": "elasticsearch", "input.type": "log", "log.level": "INFO", "log.offset": 1668, @@ -152,8 +152,8 @@ "@timestamp": "2018-07-03T11:45:48,548", "elasticsearch.node.name": "srvmulpvlsk252_md", "elasticsearch.server.component": "o.e.d.z.ZenDiscovery", - "fileset.module": "elasticsearch", - "fileset.name": "server", + "event.dataset": "server", + "event.module": "elasticsearch", "input.type": "log", "log.flags": [ "multiline" @@ -166,8 +166,8 @@ { "@timestamp": "2018-07-03T11:45:52,666", "elasticsearch.server.component": "r.suppressed", - "fileset.module": "elasticsearch", - "fileset.name": "server", + "event.dataset": "server", + "event.module": "elasticsearch", "input.type": "log", "log.flags": [ "multiline" @@ -180,8 +180,8 @@ { "@timestamp": "2018-07-03T11:48:02,552", "elasticsearch.server.component": "r.suppressed", - "fileset.module": "elasticsearch", - "fileset.name": "server", + "event.dataset": "server", + "event.module": "elasticsearch", "input.type": "log", "log.flags": [ "multiline" @@ -197,8 +197,8 @@ "elasticsearch.server.component": "o.e.m.j.JvmGcMonitorService", "elasticsearch.server.gc.young.one": "3449979", "elasticsearch.server.gc.young.two": "986594", - "fileset.module": "elasticsearch", - "fileset.name": "server", + "event.dataset": "server", + "event.module": "elasticsearch", "input.type": "log", "log.flags": [ "multiline" @@ -213,8 +213,8 @@ "elasticsearch.node.name": "srvmulpvlsk252_md", "elasticsearch.server.component": "o.e.m.j.JvmGcMonitorService", "elasticsearch.server.gc_overhead": "3449992", - "fileset.module": "elasticsearch", - "fileset.name": "server", + "event.dataset": "server", + "event.module": "elasticsearch", "input.type": "log", "log.level": "WARN", "log.offset": 10205, @@ -225,8 +225,8 @@ "@timestamp": "2018-07-03T11:48:02,541", "elasticsearch.node.name": "srvmulpvlsk252_md", "elasticsearch.server.component": "o.e.a.b.TransportShardBulkAction", - "fileset.module": "elasticsearch", - "fileset.name": "server", + "event.dataset": "server", + "event.module": "elasticsearch", "input.type": "log", "log.level": "WARN", "log.offset": 10354, @@ -237,8 +237,8 @@ "@timestamp": "2018-07-03T20:10:07,376", "elasticsearch.node.name": "srvmulpvlsk252_md", "elasticsearch.server.component": "o.e.x.m.MonitoringService", - "fileset.module": "elasticsearch", - "fileset.name": "server", + "event.dataset": "server", + "event.module": "elasticsearch", "input.type": "log", "log.flags": [ "multiline" diff --git a/filebeat/module/elasticsearch/slowlog/test/test.log-expected.json b/filebeat/module/elasticsearch/slowlog/test/test.log-expected.json index fb2ebe22985..7710e282a80 100644 --- a/filebeat/module/elasticsearch/slowlog/test/test.log-expected.json +++ b/filebeat/module/elasticsearch/slowlog/test/test.log-expected.json @@ -13,8 +13,8 @@ "elasticsearch.slowlog.total_hits": 19435, "elasticsearch.slowlog.total_shards": 1, "elasticsearch.slowlog.types": "", - "fileset.module": "elasticsearch", - "fileset.name": "slowlog", + "event.dataset": "slowlog", + "event.module": "elasticsearch", "input.type": "log", "log.level": "INFO", "log.offset": 0, @@ -35,8 +35,8 @@ "elasticsearch.slowlog.total_hits": 19435, "elasticsearch.slowlog.total_shards": 1, "elasticsearch.slowlog.types": "", - "fileset.module": "elasticsearch", - "fileset.name": "slowlog", + "event.dataset": "slowlog", + "event.module": "elasticsearch", "input.type": "log", "log.level": "INFO", "log.offset": 265, @@ -57,8 +57,8 @@ "elasticsearch.slowlog.total_hits": 0, "elasticsearch.slowlog.total_shards": 1, "elasticsearch.slowlog.types": "", - "fileset.module": "elasticsearch", - "fileset.name": "slowlog", + "event.dataset": "slowlog", + "event.module": "elasticsearch", "input.type": "log", "log.level": "INFO", "log.offset": 532, @@ -79,8 +79,8 @@ "elasticsearch.slowlog.total_hits": 0, "elasticsearch.slowlog.total_shards": 1, "elasticsearch.slowlog.types": "", - "fileset.module": "elasticsearch", - "fileset.name": "slowlog", + "event.dataset": "slowlog", + "event.module": "elasticsearch", "input.type": "log", "log.level": "INFO", "log.offset": 1999, @@ -99,8 +99,8 @@ "elasticsearch.slowlog.took": "1.4ms", "elasticsearch.slowlog.took_millis": 1, "elasticsearch.slowlog.type": "doc", - "fileset.module": "elasticsearch", - "fileset.name": "slowlog", + "event.dataset": "slowlog", + "event.module": "elasticsearch", "input.type": "log", "log.level": "INFO", "log.offset": 3462, @@ -119,8 +119,8 @@ "elasticsearch.slowlog.took": "1.7ms", "elasticsearch.slowlog.took_millis": 1, "elasticsearch.slowlog.type": "doc", - "fileset.module": "elasticsearch", - "fileset.name": "slowlog", + "event.dataset": "slowlog", + "event.module": "elasticsearch", "input.type": "log", "log.flags": [ "multiline" diff --git a/filebeat/module/haproxy/log/test/default.log-expected.json b/filebeat/module/haproxy/log/test/default.log-expected.json index 32778aa494d..99a36d83793 100644 --- a/filebeat/module/haproxy/log/test/default.log-expected.json +++ b/filebeat/module/haproxy/log/test/default.log-expected.json @@ -1,8 +1,8 @@ [ { "@timestamp": "2018-09-20T15:42:59.000Z", - "fileset.module": "haproxy", - "fileset.name": "log", + "event.dataset": "log", + "event.module": "haproxy", "haproxy.client.ip": "1.2.3.4", "haproxy.client.port": "40780", "haproxy.destination.ip": "1.2.3.4", diff --git a/filebeat/module/haproxy/log/test/haproxy.log-expected.json b/filebeat/module/haproxy/log/test/haproxy.log-expected.json index 7cdc78b77d9..13c503f8b0d 100644 --- a/filebeat/module/haproxy/log/test/haproxy.log-expected.json +++ b/filebeat/module/haproxy/log/test/haproxy.log-expected.json @@ -1,8 +1,8 @@ [ { "@timestamp": "2018-07-30T09:03:52.726Z", - "fileset.module": "haproxy", - "fileset.name": "log", + "event.dataset": "log", + "event.module": "haproxy", "haproxy.backend_name": "docs_microservice", "haproxy.backend_queue": 0, "haproxy.bytes_read": 168, diff --git a/filebeat/module/haproxy/log/test/tcplog.log-expected.json b/filebeat/module/haproxy/log/test/tcplog.log-expected.json index c3a8ec971e7..f9ef4f67ece 100644 --- a/filebeat/module/haproxy/log/test/tcplog.log-expected.json +++ b/filebeat/module/haproxy/log/test/tcplog.log-expected.json @@ -1,8 +1,8 @@ [ { "@timestamp": "2018-09-20T15:44:23.285Z", - "fileset.module": "haproxy", - "fileset.name": "log", + "event.dataset": "log", + "event.module": "haproxy", "haproxy.backend_name": "app", "haproxy.backend_queue": 0, "haproxy.bytes_read": 212, diff --git a/filebeat/module/icinga/debug/test/test.log-expected.json b/filebeat/module/icinga/debug/test/test.log-expected.json index e382d788f4a..d412a561741 100644 --- a/filebeat/module/icinga/debug/test/test.log-expected.json +++ b/filebeat/module/icinga/debug/test/test.log-expected.json @@ -1,8 +1,8 @@ [ { "@timestamp": "2017-04-04T11:43:09.000Z", - "fileset.module": "icinga", - "fileset.name": "debug", + "event.dataset": "debug", + "event.module": "icinga", "icinga.debug.facility": "GraphiteWriter", "icinga.debug.message": "Add to metric list:'icinga2.demo.services.procs.procs.perfdata.procs.warn 250 1491306189'.", "icinga.debug.severity": "debug", @@ -11,8 +11,8 @@ }, { "@timestamp": "2017-04-04T11:43:09.000Z", - "fileset.module": "icinga", - "fileset.name": "debug", + "event.dataset": "debug", + "event.module": "icinga", "icinga.debug.facility": "IdoMysqlConnection", "icinga.debug.message": "Query: UPDATE icinga_servicestatus SET acknowledgement_type = '0', active_checks_enabled = '1', check_command = 'mysql_health', check_source = 'demo', check_type = '0', current_check_attempt = '1', current_notification_number = '180', current_state = '2', endpoint_object_id = 242, event_handler = '', event_handler_enabled = '1', execution_time = '0.355594', flap_detection_enabled = '0', has_been_checked = '1', instance_id = 1, is_flapping = '0', is_reachable = '1', last_check = FROM_UNIXTIME(1491306189), last_hard_state = '2', last_hard_state_change = FROM_UNIXTIME(1491290599), last_notification = FROM_UNIXTIME(1491304989), last_state_change = FROM_UNIXTIME(1491290599), last_time_critical = FROM_UNIXTIME(1491306189), last_time_unknown = FROM_UNIXTIME(1491290589), latency = '0.001466', long_output = '', max_check_attempts = '5', next_check = FROM_UNIXTIME(1491306198), next_notification = FROM_UNIXTIME(1491306789), normal_check_interval = '0.166667', notifications_enabled = '1', original_attributes = 'null', output = 'CRITICAL - cannot connect to information_schema. Access denied for user \\'test1\\'@\\'blerims-mbp.int.netways.de\\' (using password: YES)', passive_checks_enabled = '1', percent_state_change = '0', perfdata = '', problem_has_been_acknowledged = '0', process_performance_data = '1', retry_check_interval = '0.166667', scheduled_downtime_depth = '0', service_object_id = 333, should_be_scheduled = '1', state_type = '1', status_update_time = FROM_UNIXTIME(1491306189) WHERE service_object_id = 333", "icinga.debug.severity": "debug", @@ -21,8 +21,8 @@ }, { "@timestamp": "2017-04-04T11:43:11.000Z", - "fileset.module": "icinga", - "fileset.name": "debug", + "event.dataset": "debug", + "event.module": "icinga", "icinga.debug.facility": "Process", "icinga.debug.message": "Running command '/usr/lib/nagios/plugins/check_ping' '-H' 'mysql.icinga.com' '-c' '5000,100%' '-w' '3000,80%': PID 8288", "icinga.debug.severity": "notice", diff --git a/filebeat/module/icinga/main/test/test.log-expected.json b/filebeat/module/icinga/main/test/test.log-expected.json index aaf30988997..cc324c7ec14 100644 --- a/filebeat/module/icinga/main/test/test.log-expected.json +++ b/filebeat/module/icinga/main/test/test.log-expected.json @@ -1,8 +1,8 @@ [ { "@timestamp": "2017-04-04T09:16:34.000Z", - "fileset.module": "icinga", - "fileset.name": "main", + "event.dataset": "main", + "event.module": "icinga", "icinga.main.facility": "Notification", "icinga.main.message": "Sending 'Recovery' notification 'demo!load!mail-icingaadmin for user 'on-call'", "icinga.main.severity": "information", @@ -11,8 +11,8 @@ }, { "@timestamp": "2017-04-04T09:16:34.000Z", - "fileset.module": "icinga", - "fileset.name": "main", + "event.dataset": "main", + "event.module": "icinga", "icinga.main.facility": "PluginNotificationTask", "icinga.main.message": "Notification command for object 'demo!load' (PID: 19401, arguments: '/etc/icinga2/scripts/mail-service-notification.sh') terminated with exit code 127, output: /etc/icinga2/scripts/mail-service-notification.sh: 20: /etc/icinga2/scripts/mail-service-notification.sh: mail: not found\n/usr/bin/printf: write error: Broken pipe\n", "icinga.main.severity": "warning", @@ -24,8 +24,8 @@ }, { "@timestamp": "2017-04-04T09:16:48.000Z", - "fileset.module": "icinga", - "fileset.name": "main", + "event.dataset": "main", + "event.module": "icinga", "icinga.main.facility": "IdoMysqlConnection", "icinga.main.message": "Query queue items: 0, query rate: 5.38333/s (323/min 1610/5min 4778/15min);", "icinga.main.severity": "information", diff --git a/filebeat/module/icinga/startup/test/test.log-expected.json b/filebeat/module/icinga/startup/test/test.log-expected.json index ef4d5df383f..6e6abbc601e 100644 --- a/filebeat/module/icinga/startup/test/test.log-expected.json +++ b/filebeat/module/icinga/startup/test/test.log-expected.json @@ -1,8 +1,8 @@ [ { - "@timestamp": "2018-11-06T07:15:39.844Z", - "fileset.module": "icinga", - "fileset.name": "startup", + "@timestamp": "2018-11-06T08:49:49.239Z", + "event.dataset": "startup", + "event.module": "icinga", "icinga.startup.facility": "cli", "icinga.startup.message": "Icinga application loader (version: r2.6.3-1)", "icinga.startup.severity": "information", @@ -10,9 +10,9 @@ "log.offset": 0 }, { - "@timestamp": "2018-11-06T07:15:39.844Z", - "fileset.module": "icinga", - "fileset.name": "startup", + "@timestamp": "2018-11-06T08:49:49.239Z", + "event.dataset": "startup", + "event.module": "icinga", "icinga.startup.facility": "cli", "icinga.startup.message": "Loading configuration file(s).", "icinga.startup.severity": "information", diff --git a/filebeat/module/iis/access/test/test.log-expected.json b/filebeat/module/iis/access/test/test.log-expected.json index 44e88e68bc4..83f130f4783 100644 --- a/filebeat/module/iis/access/test/test.log-expected.json +++ b/filebeat/module/iis/access/test/test.log-expected.json @@ -1,8 +1,8 @@ [ { "@timestamp": "2018-01-01T08:09:10.000Z", - "fileset.module": "iis", - "fileset.name": "access", + "event.dataset": "access", + "event.module": "iis", "iis.access.geoip.city_name": "Berlin", "iis.access.geoip.continent_name": "Europe", "iis.access.geoip.country_iso_code": "DE", @@ -34,8 +34,8 @@ }, { "@timestamp": "2018-01-01T09:10:11.000Z", - "fileset.module": "iis", - "fileset.name": "access", + "event.dataset": "access", + "event.module": "iis", "iis.access.body_received.bytes": "456", "iis.access.body_sent.bytes": "123", "iis.access.cookie": "-", @@ -64,8 +64,8 @@ }, { "@timestamp": "2018-01-01T10:11:12.000Z", - "fileset.module": "iis", - "fileset.name": "access", + "event.dataset": "access", + "event.module": "iis", "iis.access.body_received.bytes": "456", "iis.access.body_sent.bytes": "123", "iis.access.cookie": "-", diff --git a/filebeat/module/iis/error/test/test.log-expected.json b/filebeat/module/iis/error/test/test.log-expected.json index 80a1dc9c7c6..3e1e335b7fa 100644 --- a/filebeat/module/iis/error/test/test.log-expected.json +++ b/filebeat/module/iis/error/test/test.log-expected.json @@ -1,8 +1,8 @@ [ { "@timestamp": "2018-01-01T08:09:10.000Z", - "fileset.module": "iis", - "fileset.name": "error", + "event.dataset": "error", + "event.module": "iis", "iis.error.http_version": "1.1", "iis.error.method": "GET", "iis.error.queue_name": "-", @@ -18,8 +18,8 @@ }, { "@timestamp": "2018-01-01T09:10:11.000Z", - "fileset.module": "iis", - "fileset.name": "error", + "event.dataset": "error", + "event.module": "iis", "iis.error.geoip.city_name": "Berlin", "iis.error.geoip.continent_name": "Europe", "iis.error.geoip.country_iso_code": "DE", @@ -42,8 +42,8 @@ }, { "@timestamp": "2018-01-01T10:11:12.000Z", - "fileset.module": "iis", - "fileset.name": "error", + "event.dataset": "error", + "event.module": "iis", "iis.error.geoip.city_name": "Berlin", "iis.error.geoip.continent_name": "Europe", "iis.error.geoip.country_iso_code": "DE", @@ -66,8 +66,8 @@ }, { "@timestamp": "2018-01-01T11:12:13.000Z", - "fileset.module": "iis", - "fileset.name": "error", + "event.dataset": "error", + "event.module": "iis", "iis.error.geoip.city_name": "Berlin", "iis.error.geoip.continent_name": "Europe", "iis.error.geoip.country_iso_code": "DE", diff --git a/filebeat/module/kafka/log/test/controller.log-expected.json b/filebeat/module/kafka/log/test/controller.log-expected.json index f622e6ed0f7..2c8f20b4fe8 100644 --- a/filebeat/module/kafka/log/test/controller.log-expected.json +++ b/filebeat/module/kafka/log/test/controller.log-expected.json @@ -1,8 +1,8 @@ [ { "@timestamp": "2017-08-04T10:48:21.048Z", - "fileset.module": "kafka", - "fileset.name": "log", + "event.dataset": "log", + "event.module": "kafka", "input.type": "log", "kafka.log.class": "kafka.controller.ControllerEventManager$ControllerEventThread", "kafka.log.component": "controller-event-thread", @@ -13,8 +13,8 @@ }, { "@timestamp": "2017-08-04T10:48:21.063Z", - "fileset.module": "kafka", - "fileset.name": "log", + "event.dataset": "log", + "event.module": "kafka", "input.type": "log", "kafka.log.class": "kafka.controller.KafkaController", "kafka.log.component": "Controller 0", @@ -25,8 +25,8 @@ }, { "@timestamp": "2017-08-04T10:48:21.064Z", - "fileset.module": "kafka", - "fileset.name": "log", + "event.dataset": "log", + "event.module": "kafka", "input.type": "log", "kafka.log.class": "kafka.controller.KafkaController", "kafka.log.component": "Controller 0", @@ -37,8 +37,8 @@ }, { "@timestamp": "2017-08-04T10:48:21.082Z", - "fileset.module": "kafka", - "fileset.name": "log", + "event.dataset": "log", + "event.module": "kafka", "input.type": "log", "kafka.log.class": "kafka.controller.KafkaController", "kafka.log.component": "Controller 0", @@ -49,8 +49,8 @@ }, { "@timestamp": "2017-08-04T10:48:21.085Z", - "fileset.module": "kafka", - "fileset.name": "log", + "event.dataset": "log", + "event.module": "kafka", "input.type": "log", "kafka.log.class": "kafka.controller.KafkaController", "kafka.log.component": "Controller 0", @@ -61,8 +61,8 @@ }, { "@timestamp": "2017-08-04T10:48:21.154Z", - "fileset.module": "kafka", - "fileset.name": "log", + "event.dataset": "log", + "event.module": "kafka", "input.type": "log", "kafka.log.class": "kafka.controller.ReplicaStateMachine", "kafka.log.component": "Replica state machine on controller 0", @@ -73,8 +73,8 @@ }, { "@timestamp": "2017-08-04T10:48:21.156Z", - "fileset.module": "kafka", - "fileset.name": "log", + "event.dataset": "log", + "event.module": "kafka", "input.type": "log", "kafka.log.class": "kafka.controller.PartitionStateMachine", "kafka.log.component": "Partition state machine on Controller 0", @@ -85,8 +85,8 @@ }, { "@timestamp": "2017-08-04T10:48:21.157Z", - "fileset.module": "kafka", - "fileset.name": "log", + "event.dataset": "log", + "event.module": "kafka", "input.type": "log", "kafka.log.class": "kafka.controller.KafkaController", "kafka.log.component": "Controller 0", @@ -97,8 +97,8 @@ }, { "@timestamp": "2017-08-04T10:48:21.165Z", - "fileset.module": "kafka", - "fileset.name": "log", + "event.dataset": "log", + "event.module": "kafka", "input.type": "log", "kafka.log.class": "kafka.controller.PartitionStateMachine", "kafka.log.component": "Partition state machine on Controller 0", @@ -109,8 +109,8 @@ }, { "@timestamp": "2017-08-04T11:44:22.588Z", - "fileset.module": "kafka", - "fileset.name": "log", + "event.dataset": "log", + "event.module": "kafka", "input.type": "log", "kafka.log.class": "kafka.controller.KafkaController", "kafka.log.component": "Controller 0", @@ -121,8 +121,8 @@ }, { "@timestamp": "2017-08-04T11:44:25.094Z", - "fileset.module": "kafka", - "fileset.name": "log", + "event.dataset": "log", + "event.module": "kafka", "input.type": "log", "kafka.log.class": "kafka.controller.ControllerEventManager$ControllerEventThread", "kafka.log.component": "controller-event-thread", @@ -133,8 +133,8 @@ }, { "@timestamp": "2017-08-04T11:44:25.095Z", - "fileset.module": "kafka", - "fileset.name": "log", + "event.dataset": "log", + "event.module": "kafka", "input.type": "log", "kafka.log.class": "kafka.controller.ControllerEventManager$ControllerEventThread", "kafka.log.component": "controller-event-thread", @@ -145,8 +145,8 @@ }, { "@timestamp": "2017-08-04T11:44:25.097Z", - "fileset.module": "kafka", - "fileset.name": "log", + "event.dataset": "log", + "event.module": "kafka", "input.type": "log", "kafka.log.class": "kafka.controller.ControllerEventManager$ControllerEventThread", "kafka.log.component": "controller-event-thread", @@ -157,8 +157,8 @@ }, { "@timestamp": "2017-08-04T11:44:25.099Z", - "fileset.module": "kafka", - "fileset.name": "log", + "event.dataset": "log", + "event.module": "kafka", "input.type": "log", "kafka.log.class": "kafka.controller.KafkaController", "kafka.log.component": "Controller 0", @@ -169,8 +169,8 @@ }, { "@timestamp": "2017-08-04T11:44:25.100Z", - "fileset.module": "kafka", - "fileset.name": "log", + "event.dataset": "log", + "event.module": "kafka", "input.type": "log", "kafka.log.class": "kafka.controller.KafkaController", "kafka.log.component": "Controller 0", @@ -181,8 +181,8 @@ }, { "@timestamp": "2017-08-04T11:44:25.105Z", - "fileset.module": "kafka", - "fileset.name": "log", + "event.dataset": "log", + "event.module": "kafka", "input.type": "log", "kafka.log.class": "kafka.controller.PartitionStateMachine", "kafka.log.component": "Partition state machine on Controller 0", @@ -193,8 +193,8 @@ }, { "@timestamp": "2017-08-04T11:44:25.111Z", - "fileset.module": "kafka", - "fileset.name": "log", + "event.dataset": "log", + "event.module": "kafka", "input.type": "log", "kafka.log.class": "kafka.controller.ReplicaStateMachine", "kafka.log.component": "Replica state machine on controller 0", @@ -205,8 +205,8 @@ }, { "@timestamp": "2017-08-04T11:44:25.112Z", - "fileset.module": "kafka", - "fileset.name": "log", + "event.dataset": "log", + "event.module": "kafka", "input.type": "log", "kafka.log.class": "kafka.controller.RequestSendThread", "kafka.log.component": "Controller-0-to-broker-0-send-thread", @@ -217,8 +217,8 @@ }, { "@timestamp": "2017-08-04T11:44:25.112Z", - "fileset.module": "kafka", - "fileset.name": "log", + "event.dataset": "log", + "event.module": "kafka", "input.type": "log", "kafka.log.class": "kafka.controller.RequestSendThread", "kafka.log.component": "Controller-0-to-broker-0-send-thread", @@ -229,8 +229,8 @@ }, { "@timestamp": "2017-08-04T11:44:25.113Z", - "fileset.module": "kafka", - "fileset.name": "log", + "event.dataset": "log", + "event.module": "kafka", "input.type": "log", "kafka.log.class": "kafka.controller.RequestSendThread", "kafka.log.component": "Controller-0-to-broker-0-send-thread", diff --git a/filebeat/module/kafka/log/test/server.log-expected.json b/filebeat/module/kafka/log/test/server.log-expected.json index 94e8544a4a4..973869080f3 100644 --- a/filebeat/module/kafka/log/test/server.log-expected.json +++ b/filebeat/module/kafka/log/test/server.log-expected.json @@ -1,8 +1,8 @@ [ { "@timestamp": "2017-08-04T10:48:20.377Z", - "fileset.module": "kafka", - "fileset.name": "log", + "event.dataset": "log", + "event.module": "kafka", "input.type": "log", "kafka.log.class": "kafka.server.KafkaServer", "kafka.log.component": "unknown", @@ -13,8 +13,8 @@ }, { "@timestamp": "2017-08-04T10:48:20.379Z", - "fileset.module": "kafka", - "fileset.name": "log", + "event.dataset": "log", + "event.module": "kafka", "input.type": "log", "kafka.log.class": "kafka.server.KafkaServer", "kafka.log.component": "unknown", @@ -25,8 +25,8 @@ }, { "@timestamp": "2017-08-04T10:48:20.400Z", - "fileset.module": "kafka", - "fileset.name": "log", + "event.dataset": "log", + "event.module": "kafka", "input.type": "log", "kafka.log.class": "org.apache.zookeeper.ZooKeeper", "kafka.log.component": "unknown", @@ -37,8 +37,8 @@ }, { "@timestamp": "2017-08-04T10:48:20.400Z", - "fileset.module": "kafka", - "fileset.name": "log", + "event.dataset": "log", + "event.module": "kafka", "input.type": "log", "kafka.log.class": "org.apache.zookeeper.ZooKeeper", "kafka.log.component": "unknown", @@ -49,8 +49,8 @@ }, { "@timestamp": "2017-08-04T10:48:20.401Z", - "fileset.module": "kafka", - "fileset.name": "log", + "event.dataset": "log", + "event.module": "kafka", "input.type": "log", "kafka.log.class": "org.apache.zookeeper.ZooKeeper", "kafka.log.component": "unknown", @@ -61,8 +61,8 @@ }, { "@timestamp": "2017-08-04T10:48:20.413Z", - "fileset.module": "kafka", - "fileset.name": "log", + "event.dataset": "log", + "event.module": "kafka", "input.type": "log", "kafka.log.class": "org.I0Itec.zkclient.ZkClient", "kafka.log.component": "unknown", @@ -73,8 +73,8 @@ }, { "@timestamp": "2017-08-04T10:48:20.415Z", - "fileset.module": "kafka", - "fileset.name": "log", + "event.dataset": "log", + "event.module": "kafka", "input.type": "log", "kafka.log.class": "org.apache.zookeeper.ClientCnxn", "kafka.log.component": "unknown", @@ -85,8 +85,8 @@ }, { "@timestamp": "2017-08-04T10:48:20.420Z", - "fileset.module": "kafka", - "fileset.name": "log", + "event.dataset": "log", + "event.module": "kafka", "input.type": "log", "kafka.log.class": "org.apache.zookeeper.ClientCnxn", "kafka.log.component": "unknown", @@ -97,8 +97,8 @@ }, { "@timestamp": "2017-08-04T10:48:20.457Z", - "fileset.module": "kafka", - "fileset.name": "log", + "event.dataset": "log", + "event.module": "kafka", "input.type": "log", "kafka.log.class": "org.apache.zookeeper.ClientCnxn", "kafka.log.component": "unknown", @@ -109,8 +109,8 @@ }, { "@timestamp": "2017-08-04T10:48:20.458Z", - "fileset.module": "kafka", - "fileset.name": "log", + "event.dataset": "log", + "event.module": "kafka", "input.type": "log", "kafka.log.class": "org.I0Itec.zkclient.ZkClient", "kafka.log.component": "unknown", @@ -121,8 +121,8 @@ }, { "@timestamp": "2017-08-04T10:48:20.748Z", - "fileset.module": "kafka", - "fileset.name": "log", + "event.dataset": "log", + "event.module": "kafka", "input.type": "log", "kafka.log.class": "kafka.server.BrokerMetadataCheckpoint", "kafka.log.component": "unknown", @@ -133,8 +133,8 @@ }, { "@timestamp": "2017-08-04T10:48:20.800Z", - "fileset.module": "kafka", - "fileset.name": "log", + "event.dataset": "log", + "event.module": "kafka", "input.type": "log", "kafka.log.class": "kafka.server.ClientQuotaManager$ThrottledRequestReaper", "kafka.log.component": "ThrottledRequestReaper-Fetch", @@ -145,8 +145,8 @@ }, { "@timestamp": "2017-08-04T10:48:20.866Z", - "fileset.module": "kafka", - "fileset.name": "log", + "event.dataset": "log", + "event.module": "kafka", "input.type": "log", "kafka.log.class": "kafka.log.LogManager", "kafka.log.component": "unknown", @@ -157,8 +157,8 @@ }, { "@timestamp": "2017-08-04T10:48:20.873Z", - "fileset.module": "kafka", - "fileset.name": "log", + "event.dataset": "log", + "event.module": "kafka", "input.type": "log", "kafka.log.class": "kafka.log.LogManager", "kafka.log.component": "unknown", @@ -169,8 +169,8 @@ }, { "@timestamp": "2017-08-04T10:48:21.062Z", - "fileset.module": "kafka", - "fileset.name": "log", + "event.dataset": "log", + "event.module": "kafka", "input.type": "log", "kafka.log.class": "kafka.server.DelayedOperationPurgatory$ExpiredOperationReaper", "kafka.log.component": "ExpirationReaper-0-Heartbeat", @@ -181,8 +181,8 @@ }, { "@timestamp": "2017-08-04T10:48:21.063Z", - "fileset.module": "kafka", - "fileset.name": "log", + "event.dataset": "log", + "event.module": "kafka", "input.type": "log", "kafka.log.class": "kafka.utils.ZKCheckedEphemeral", "kafka.log.component": "unknown", @@ -193,8 +193,8 @@ }, { "@timestamp": "2017-08-04T10:48:21.095Z", - "fileset.module": "kafka", - "fileset.name": "log", + "event.dataset": "log", + "event.module": "kafka", "input.type": "log", "kafka.log.class": "kafka.coordinator.group.GroupMetadataManager", "kafka.log.component": "Group Metadata Manager on Broker 0", @@ -205,8 +205,8 @@ }, { "@timestamp": "2017-08-04T10:48:21.127Z", - "fileset.module": "kafka", - "fileset.name": "log", + "event.dataset": "log", + "event.module": "kafka", "input.type": "log", "kafka.log.class": "kafka.coordinator.transaction.ProducerIdManager", "kafka.log.component": "ProducerId Manager 0", @@ -217,8 +217,8 @@ }, { "@timestamp": "2017-08-04T10:48:21.162Z", - "fileset.module": "kafka", - "fileset.name": "log", + "event.dataset": "log", + "event.module": "kafka", "input.type": "log", "kafka.log.class": "kafka.coordinator.transaction.TransactionCoordinator", "kafka.log.component": "Transaction Coordinator 0", @@ -229,8 +229,8 @@ }, { "@timestamp": "2017-08-04T10:48:21.167Z", - "fileset.module": "kafka", - "fileset.name": "log", + "event.dataset": "log", + "event.module": "kafka", "input.type": "log", "kafka.log.class": "kafka.coordinator.transaction.TransactionMarkerChannelManager", "kafka.log.component": "Transaction Marker Channel Manager 0", diff --git a/filebeat/module/kafka/log/test/state-change-1.1.0.log-expected.json b/filebeat/module/kafka/log/test/state-change-1.1.0.log-expected.json index 71bdd6fd65b..3ca5d721555 100644 --- a/filebeat/module/kafka/log/test/state-change-1.1.0.log-expected.json +++ b/filebeat/module/kafka/log/test/state-change-1.1.0.log-expected.json @@ -1,8 +1,8 @@ [ { "@timestamp": "2018-07-16T10:17:06.489Z", - "fileset.module": "kafka", - "fileset.name": "log", + "event.dataset": "log", + "event.module": "kafka", "input.type": "log", "kafka.log.class": "state.change.logger", "kafka.log.component": "Broker id=30", diff --git a/filebeat/module/kafka/log/test/state-change-2.0.0.log-expected.json b/filebeat/module/kafka/log/test/state-change-2.0.0.log-expected.json index 3a73e53d546..dcb7a01e922 100644 --- a/filebeat/module/kafka/log/test/state-change-2.0.0.log-expected.json +++ b/filebeat/module/kafka/log/test/state-change-2.0.0.log-expected.json @@ -1,8 +1,8 @@ [ { "@timestamp": "2018-10-31T15:09:30.451Z", - "fileset.module": "kafka", - "fileset.name": "log", + "event.dataset": "log", + "event.module": "kafka", "input.type": "log", "kafka.log.class": "state.change.logger", "kafka.log.component": "Broker id=20", diff --git a/filebeat/module/kafka/log/test/state-change.log-expected.json b/filebeat/module/kafka/log/test/state-change.log-expected.json index 190201d4d2d..9cd3e1667ff 100644 --- a/filebeat/module/kafka/log/test/state-change.log-expected.json +++ b/filebeat/module/kafka/log/test/state-change.log-expected.json @@ -1,8 +1,8 @@ [ { "@timestamp": "2017-08-04T10:48:21.428Z", - "fileset.module": "kafka", - "fileset.name": "log", + "event.dataset": "log", + "event.module": "kafka", "input.type": "log", "kafka.log.class": "state.change.logger", "kafka.log.component": "unknown", diff --git a/filebeat/module/kibana/log/test/test.log-expected.json b/filebeat/module/kibana/log/test/test.log-expected.json index 7733cf68972..3f4041b7132 100644 --- a/filebeat/module/kibana/log/test/test.log-expected.json +++ b/filebeat/module/kibana/log/test/test.log-expected.json @@ -1,8 +1,8 @@ [ { "@timestamp": "2018-05-09T10:57:55.000Z", - "fileset.module": "kibana", - "fileset.name": "log", + "event.dataset": "log", + "event.module": "kibana", "http.request.method": "get", "http.response.content_length": 9, "http.response.elapsed_time": 26, @@ -35,8 +35,8 @@ }, { "@timestamp": "2018-05-09T10:59:12.000Z", - "fileset.module": "kibana", - "fileset.name": "log", + "event.dataset": "log", + "event.module": "kibana", "input.type": "log", "kibana.log.meta.type": "log", "kibana.log.tags": [ @@ -53,8 +53,8 @@ }, { "@timestamp": "2018-05-09T10:59:12.000Z", - "fileset.module": "kibana", - "fileset.name": "log", + "event.dataset": "log", + "event.module": "kibana", "input.type": "log", "kibana.log.meta.type": "log", "kibana.log.tags": [ diff --git a/filebeat/module/logstash/log/test/logstash-plain.log-expected.json b/filebeat/module/logstash/log/test/logstash-plain.log-expected.json index e3b5b19b2c4..edc112e0b2c 100644 --- a/filebeat/module/logstash/log/test/logstash-plain.log-expected.json +++ b/filebeat/module/logstash/log/test/logstash-plain.log-expected.json @@ -1,8 +1,8 @@ [ { "@timestamp": "2017-10-23T14:20:12,046", - "fileset.module": "logstash", - "fileset.name": "log", + "event.dataset": "log", + "event.module": "logstash", "input.type": "log", "log.offset": 0, "logstash.log.level": "INFO", @@ -11,8 +11,8 @@ }, { "@timestamp": "2017-11-20T03:55:00,318", - "fileset.module": "logstash", - "fileset.name": "log", + "event.dataset": "log", + "event.module": "logstash", "input.type": "log", "log.flags": [ "multiline" diff --git a/filebeat/module/logstash/slowlog/test/slowlog-plain.log-expected.json b/filebeat/module/logstash/slowlog/test/slowlog-plain.log-expected.json index 25a47c8f63e..6f16bb168c4 100644 --- a/filebeat/module/logstash/slowlog/test/slowlog-plain.log-expected.json +++ b/filebeat/module/logstash/slowlog/test/slowlog-plain.log-expected.json @@ -1,8 +1,8 @@ [ { "@timestamp": "2017-10-30T09:57:58,243", - "fileset.module": "logstash", - "fileset.name": "slowlog", + "event.dataset": "slowlog", + "event.module": "logstash", "input.type": "log", "log.offset": 0, "logstash.slowlog.event": "\"{\\\"@version\\\":\\\"1\\\",\\\"@timestamp\\\":\\\"2017-10-30T13:57:55.130Z\\\",\\\"host\\\":\\\"sashimi\\\",\\\"sequence\\\":0,\\\"message\\\":\\\"Hello world!\\\"}\"", diff --git a/filebeat/module/mongodb/log/test/mongodb-debian-3.2.11.log-expected.json b/filebeat/module/mongodb/log/test/mongodb-debian-3.2.11.log-expected.json index 81c3f44c68e..62768dc7dec 100644 --- a/filebeat/module/mongodb/log/test/mongodb-debian-3.2.11.log-expected.json +++ b/filebeat/module/mongodb/log/test/mongodb-debian-3.2.11.log-expected.json @@ -1,8 +1,8 @@ [ { "@timestamp": "2018-02-05T12:44:56.657Z", - "fileset.module": "mongodb", - "fileset.name": "log", + "event.dataset": "log", + "event.module": "mongodb", "input.type": "log", "log.offset": 0, "mongodb.log.component": "CONTROL", @@ -12,8 +12,8 @@ }, { "@timestamp": "2018-02-05T12:44:56.657Z", - "fileset.module": "mongodb", - "fileset.name": "log", + "event.dataset": "log", + "event.module": "mongodb", "input.type": "log", "log.offset": 110, "mongodb.log.component": "CONTROL", @@ -23,8 +23,8 @@ }, { "@timestamp": "2018-02-05T12:44:56.657Z", - "fileset.module": "mongodb", - "fileset.name": "log", + "event.dataset": "log", + "event.module": "mongodb", "input.type": "log", "log.offset": 180, "mongodb.log.component": "CONTROL", @@ -34,8 +34,8 @@ }, { "@timestamp": "2018-02-05T12:44:56.677Z", - "fileset.module": "mongodb", - "fileset.name": "log", + "event.dataset": "log", + "event.module": "mongodb", "input.type": "log", "log.offset": 281, "mongodb.log.component": "STORAGE", @@ -45,8 +45,8 @@ }, { "@timestamp": "2018-02-05T12:44:56.724Z", - "fileset.module": "mongodb", - "fileset.name": "log", + "event.dataset": "log", + "event.module": "mongodb", "input.type": "log", "log.offset": 621, "mongodb.log.component": "FTDC", @@ -56,8 +56,8 @@ }, { "@timestamp": "2018-02-05T12:44:56.724Z", - "fileset.module": "mongodb", - "fileset.name": "log", + "event.dataset": "log", + "event.module": "mongodb", "input.type": "log", "log.offset": 774, "mongodb.log.component": "NETWORK", @@ -67,8 +67,8 @@ }, { "@timestamp": "2018-02-05T12:44:56.744Z", - "fileset.module": "mongodb", - "fileset.name": "log", + "event.dataset": "log", + "event.module": "mongodb", "input.type": "log", "log.offset": 889, "mongodb.log.component": "NETWORK", @@ -78,8 +78,8 @@ }, { "@timestamp": "2018-02-05T12:50:55.170Z", - "fileset.module": "mongodb", - "fileset.name": "log", + "event.dataset": "log", + "event.module": "mongodb", "input.type": "log", "log.offset": 983, "mongodb.log.component": "NETWORK", @@ -89,8 +89,8 @@ }, { "@timestamp": "2018-02-05T12:50:55.487Z", - "fileset.module": "mongodb", - "fileset.name": "log", + "event.dataset": "log", + "event.module": "mongodb", "input.type": "log", "log.offset": 1087, "mongodb.log.component": "NETWORK", @@ -100,8 +100,8 @@ }, { "@timestamp": "2018-02-05T13:49:45.606Z", - "fileset.module": "mongodb", - "fileset.name": "log", + "event.dataset": "log", + "event.module": "mongodb", "input.type": "log", "log.offset": 1211, "mongodb.log.component": "CONTROL", @@ -111,8 +111,8 @@ }, { "@timestamp": "2018-02-05T13:49:45.606Z", - "fileset.module": "mongodb", - "fileset.name": "log", + "event.dataset": "log", + "event.module": "mongodb", "input.type": "log", "log.offset": 1288, "mongodb.log.component": "NETWORK", @@ -122,8 +122,8 @@ }, { "@timestamp": "2018-02-05T13:49:45.606Z", - "fileset.module": "mongodb", - "fileset.name": "log", + "event.dataset": "log", + "event.module": "mongodb", "input.type": "log", "log.offset": 1381, "mongodb.log.component": "NETWORK", @@ -133,8 +133,8 @@ }, { "@timestamp": "2018-02-05T13:49:45.606Z", - "fileset.module": "mongodb", - "fileset.name": "log", + "event.dataset": "log", + "event.module": "mongodb", "input.type": "log", "log.offset": 1500, "mongodb.log.component": "NETWORK", @@ -144,8 +144,8 @@ }, { "@timestamp": "2018-02-05T13:49:45.606Z", - "fileset.module": "mongodb", - "fileset.name": "log", + "event.dataset": "log", + "event.module": "mongodb", "input.type": "log", "log.offset": 1601, "mongodb.log.component": "NETWORK", @@ -155,8 +155,8 @@ }, { "@timestamp": "2018-02-05T13:49:45.688Z", - "fileset.module": "mongodb", - "fileset.name": "log", + "event.dataset": "log", + "event.module": "mongodb", "input.type": "log", "log.offset": 1702, "mongodb.log.component": "STORAGE", @@ -166,8 +166,8 @@ }, { "@timestamp": "2018-02-05T12:44:56.657Z", - "fileset.module": "mongodb", - "fileset.name": "log", + "event.dataset": "log", + "event.module": "mongodb", "input.type": "log", "log.offset": 1797, "mongodb.log.component": "CONTROL", @@ -177,8 +177,8 @@ }, { "@timestamp": "2018-02-05T12:44:56.657Z", - "fileset.module": "mongodb", - "fileset.name": "log", + "event.dataset": "log", + "event.module": "mongodb", "input.type": "log", "log.offset": 1872, "mongodb.log.component": "CONTROL", @@ -188,8 +188,8 @@ }, { "@timestamp": "2018-02-05T12:44:56.657Z", - "fileset.module": "mongodb", - "fileset.name": "log", + "event.dataset": "log", + "event.module": "mongodb", "input.type": "log", "log.offset": 1947, "mongodb.log.component": "CONTROL", @@ -199,8 +199,8 @@ }, { "@timestamp": "2018-02-05T12:44:56.657Z", - "fileset.module": "mongodb", - "fileset.name": "log", + "event.dataset": "log", + "event.module": "mongodb", "input.type": "log", "log.offset": 2024, "mongodb.log.component": "CONTROL", @@ -210,8 +210,8 @@ }, { "@timestamp": "2018-02-05T12:50:55.170Z", - "fileset.module": "mongodb", - "fileset.name": "log", + "event.dataset": "log", + "event.module": "mongodb", "input.type": "log", "log.offset": 2361, "mongodb.log.component": "NETWORK", @@ -221,8 +221,8 @@ }, { "@timestamp": "2018-02-05T12:50:56.180Z", - "fileset.module": "mongodb", - "fileset.name": "log", + "event.dataset": "log", + "event.module": "mongodb", "input.type": "log", "log.offset": 2485, "mongodb.log.component": "NETWORK", @@ -232,8 +232,8 @@ }, { "@timestamp": "2018-02-05T13:15:42.095Z", - "fileset.module": "mongodb", - "fileset.name": "log", + "event.dataset": "log", + "event.module": "mongodb", "input.type": "log", "log.offset": 2589, "mongodb.log.component": "NETWORK", @@ -243,8 +243,8 @@ }, { "@timestamp": "2018-02-05T13:49:45.606Z", - "fileset.module": "mongodb", - "fileset.name": "log", + "event.dataset": "log", + "event.module": "mongodb", "input.type": "log", "log.offset": 2693, "mongodb.log.component": "NETWORK", @@ -254,8 +254,8 @@ }, { "@timestamp": "2018-02-05T13:49:45.606Z", - "fileset.module": "mongodb", - "fileset.name": "log", + "event.dataset": "log", + "event.module": "mongodb", "input.type": "log", "log.offset": 2804, "mongodb.log.component": "STORAGE", @@ -265,8 +265,8 @@ }, { "@timestamp": "2018-02-05T13:49:45.688Z", - "fileset.module": "mongodb", - "fileset.name": "log", + "event.dataset": "log", + "event.module": "mongodb", "input.type": "log", "log.offset": 2902, "mongodb.log.component": "CONTROL", @@ -276,8 +276,8 @@ }, { "@timestamp": "2018-02-05T12:44:56.657Z", - "fileset.module": "mongodb", - "fileset.name": "log", + "event.dataset": "log", + "event.module": "mongodb", "input.type": "log", "log.offset": 2982, "mongodb.log.component": "CONTROL", @@ -287,8 +287,8 @@ }, { "@timestamp": "2018-02-05T12:44:56.657Z", - "fileset.module": "mongodb", - "fileset.name": "log", + "event.dataset": "log", + "event.module": "mongodb", "input.type": "log", "log.offset": 3123, "mongodb.log.component": "CONTROL", @@ -298,8 +298,8 @@ }, { "@timestamp": "2018-02-05T12:44:56.657Z", - "fileset.module": "mongodb", - "fileset.name": "log", + "event.dataset": "log", + "event.module": "mongodb", "input.type": "log", "log.offset": 3199, "mongodb.log.component": "CONTROL", @@ -309,8 +309,8 @@ }, { "@timestamp": "2018-02-05T12:50:55.487Z", - "fileset.module": "mongodb", - "fileset.name": "log", + "event.dataset": "log", + "event.module": "mongodb", "input.type": "log", "log.offset": 3279, "mongodb.log.component": "NETWORK", @@ -320,8 +320,8 @@ }, { "@timestamp": "2018-02-05T12:50:56.180Z", - "fileset.module": "mongodb", - "fileset.name": "log", + "event.dataset": "log", + "event.module": "mongodb", "input.type": "log", "log.offset": 3383, "mongodb.log.component": "NETWORK", @@ -331,8 +331,8 @@ }, { "@timestamp": "2018-02-05T13:11:41.401Z", - "fileset.module": "mongodb", - "fileset.name": "log", + "event.dataset": "log", + "event.module": "mongodb", "input.type": "log", "log.offset": 3507, "mongodb.log.component": "NETWORK", @@ -342,8 +342,8 @@ }, { "@timestamp": "2018-02-05T13:49:45.605Z", - "fileset.module": "mongodb", - "fileset.name": "log", + "event.dataset": "log", + "event.module": "mongodb", "input.type": "log", "log.offset": 3631, "mongodb.log.component": "CONTROL", @@ -353,8 +353,8 @@ }, { "@timestamp": "2018-02-05T13:49:45.605Z", - "fileset.module": "mongodb", - "fileset.name": "log", + "event.dataset": "log", + "event.module": "mongodb", "input.type": "log", "log.offset": 3762, "mongodb.log.component": "FTDC", @@ -364,8 +364,8 @@ }, { "@timestamp": "2018-02-05T13:49:45.606Z", - "fileset.module": "mongodb", - "fileset.name": "log", + "event.dataset": "log", + "event.module": "mongodb", "input.type": "log", "log.offset": 3875, "mongodb.log.component": "NETWORK", diff --git a/filebeat/module/nginx/access/test/test.log-expected.json b/filebeat/module/nginx/access/test/test.log-expected.json index 28a977e6ac0..97e9f2df1a0 100644 --- a/filebeat/module/nginx/access/test/test.log-expected.json +++ b/filebeat/module/nginx/access/test/test.log-expected.json @@ -1,8 +1,8 @@ [ { "@timestamp": "2016-12-07T10:05:07.000Z", - "fileset.module": "nginx", - "fileset.name": "access", + "event.dataset": "access", + "event.module": "nginx", "input.type": "log", "log.offset": 0, "nginx.access.body_sent.bytes": "571", @@ -30,8 +30,8 @@ }, { "@timestamp": "2017-05-29T19:02:48.000Z", - "fileset.module": "nginx", - "fileset.name": "access", + "event.dataset": "access", + "event.module": "nginx", "input.type": "log", "log.offset": 183, "nginx.access.body_sent.bytes": "612", @@ -56,8 +56,8 @@ }, { "@timestamp": "2016-12-07T10:05:07.000Z", - "fileset.module": "nginx", - "fileset.name": "access", + "event.dataset": "access", + "event.module": "nginx", "input.type": "log", "log.offset": 341, "nginx.access.body_sent.bytes": "571", @@ -92,8 +92,8 @@ }, { "@timestamp": "2016-12-07T10:05:07.000Z", - "fileset.module": "nginx", - "fileset.name": "access", + "event.dataset": "access", + "event.module": "nginx", "input.type": "log", "log.offset": 527, "nginx.access.body_sent.bytes": "571", @@ -126,8 +126,8 @@ }, { "@timestamp": "2016-01-22T13:18:29.000Z", - "fileset.module": "nginx", - "fileset.name": "access", + "event.dataset": "access", + "event.module": "nginx", "input.type": "log", "log.offset": 693, "nginx.access.body_sent.bytes": "25507", @@ -159,8 +159,8 @@ }, { "@timestamp": "2016-12-30T06:47:09.000Z", - "fileset.module": "nginx", - "fileset.name": "access", + "event.dataset": "access", + "event.module": "nginx", "input.type": "log", "log.offset": 845, "nginx.access.body_sent.bytes": "8571", @@ -190,8 +190,8 @@ }, { "@timestamp": "2018-04-12T07:48:40.000Z", - "fileset.module": "nginx", - "fileset.name": "access", + "event.dataset": "access", + "event.module": "nginx", "input.type": "log", "log.offset": 1085, "nginx.access.body_sent.bytes": "0", diff --git a/filebeat/module/nginx/error/test/error.log-expected.json b/filebeat/module/nginx/error/test/error.log-expected.json index 8a1aa4f6ae8..b1d5e0fb6bd 100644 --- a/filebeat/module/nginx/error/test/error.log-expected.json +++ b/filebeat/module/nginx/error/test/error.log-expected.json @@ -1,8 +1,8 @@ [ { "@timestamp": "2016-10-25T14:49:34.000Z", - "fileset.module": "nginx", - "fileset.name": "error", + "event.dataset": "error", + "event.module": "nginx", "input.type": "log", "log.offset": 0, "nginx.error.connection_id": "1", @@ -13,8 +13,8 @@ }, { "@timestamp": "2016-10-25T14:50:44.000Z", - "fileset.module": "nginx", - "fileset.name": "error", + "event.dataset": "error", + "event.module": "nginx", "input.type": "log", "log.offset": 273, "nginx.error.connection_id": "3", diff --git a/filebeat/module/osquery/result/test/test.log-expected.json b/filebeat/module/osquery/result/test/test.log-expected.json index 4db8393768d..40ae0254856 100644 --- a/filebeat/module/osquery/result/test/test.log-expected.json +++ b/filebeat/module/osquery/result/test/test.log-expected.json @@ -1,8 +1,8 @@ [ { "@timestamp": "2017-12-28T14:40:08.000Z", - "fileset.module": "osquery", - "fileset.name": "result", + "event.dataset": "result", + "event.module": "osquery", "input.type": "log", "log.offset": 0, "osquery.result.action": "removed", diff --git a/filebeat/module/postgresql/log/test/postgresql-9.6-debian-with-slowlog.log-expected.json b/filebeat/module/postgresql/log/test/postgresql-9.6-debian-with-slowlog.log-expected.json index 0553bcc232c..4598f1e87b9 100644 --- a/filebeat/module/postgresql/log/test/postgresql-9.6-debian-with-slowlog.log-expected.json +++ b/filebeat/module/postgresql/log/test/postgresql-9.6-debian-with-slowlog.log-expected.json @@ -1,8 +1,8 @@ [ { "@timestamp": "2017-07-31T13:36:42.585Z", - "fileset.module": "postgresql", - "fileset.name": "log", + "event.dataset": "log", + "event.module": "postgresql", "input.type": "log", "log.offset": 0, "message": "2017-07-31 13:36:42.585 CEST [4974] LOG: database system was shut down at 2017-06-17 16:58:04 CEST", @@ -14,8 +14,8 @@ }, { "@timestamp": "2017-07-31T13:36:42.605Z", - "fileset.module": "postgresql", - "fileset.name": "log", + "event.dataset": "log", + "event.module": "postgresql", "input.type": "log", "log.offset": 100, "message": "2017-07-31 13:36:42.605 CEST [4974] LOG: MultiXact member wraparound protections are now enabled", @@ -27,8 +27,8 @@ }, { "@timestamp": "2017-07-31T13:36:42.615Z", - "fileset.module": "postgresql", - "fileset.name": "log", + "event.dataset": "log", + "event.module": "postgresql", "input.type": "log", "log.offset": 198, "message": "2017-07-31 13:36:42.615 CEST [4978] LOG: autovacuum launcher started", @@ -40,8 +40,8 @@ }, { "@timestamp": "2017-07-31T13:36:42.616Z", - "fileset.module": "postgresql", - "fileset.name": "log", + "event.dataset": "log", + "event.module": "postgresql", "input.type": "log", "log.offset": 268, "message": "2017-07-31 13:36:42.616 CEST [4973] LOG: database system is ready to accept connections", @@ -53,8 +53,8 @@ }, { "@timestamp": "2017-07-31T13:36:42.956Z", - "fileset.module": "postgresql", - "fileset.name": "log", + "event.dataset": "log", + "event.module": "postgresql", "input.type": "log", "log.offset": 357, "message": "2017-07-31 13:36:42.956 CEST [4980] [unknown]@[unknown] LOG: incomplete startup packet", @@ -68,8 +68,8 @@ }, { "@timestamp": "2017-07-31T13:36:43.557Z", - "fileset.module": "postgresql", - "fileset.name": "log", + "event.dataset": "log", + "event.module": "postgresql", "input.type": "log", "log.flags": [ "multiline" @@ -87,8 +87,8 @@ }, { "@timestamp": "2017-07-31T13:36:44.104Z", - "fileset.module": "postgresql", - "fileset.name": "log", + "event.dataset": "log", + "event.module": "postgresql", "input.type": "log", "log.flags": [ "multiline" @@ -106,8 +106,8 @@ }, { "@timestamp": "2017-07-31T13:36:44.642Z", - "fileset.module": "postgresql", - "fileset.name": "log", + "event.dataset": "log", + "event.module": "postgresql", "input.type": "log", "log.flags": [ "multiline" @@ -125,8 +125,8 @@ }, { "@timestamp": "2017-07-31T13:39:16.249Z", - "fileset.module": "postgresql", - "fileset.name": "log", + "event.dataset": "log", + "event.module": "postgresql", "input.type": "log", "log.offset": 1727, "message": "2017-07-31 13:39:16.249 CEST [5407] postgres@users FATAL: database \"users\" does not exist", @@ -140,8 +140,8 @@ }, { "@timestamp": "2017-07-31T13:39:17.945Z", - "fileset.module": "postgresql", - "fileset.name": "log", + "event.dataset": "log", + "event.module": "postgresql", "input.type": "log", "log.offset": 1818, "message": "2017-07-31 13:39:17.945 CEST [5500] postgres@user FATAL: database \"user\" does not exist", @@ -155,8 +155,8 @@ }, { "@timestamp": "2017-07-31T13:39:21.025Z", - "fileset.module": "postgresql", - "fileset.name": "log", + "event.dataset": "log", + "event.module": "postgresql", "input.type": "log", "log.flags": [ "multiline" @@ -174,8 +174,8 @@ }, { "@timestamp": "2017-07-31T13:39:31.619Z", - "fileset.module": "postgresql", - "fileset.name": "log", + "event.dataset": "log", + "event.module": "postgresql", "input.type": "log", "log.offset": 2620, "message": "2017-07-31 13:39:31.619 CEST [5502] postgres@clients LOG: duration: 9.482 ms statement: select * from clients;", @@ -190,8 +190,8 @@ }, { "@timestamp": "2017-07-31T13:39:40.147Z", - "fileset.module": "postgresql", - "fileset.name": "log", + "event.dataset": "log", + "event.module": "postgresql", "input.type": "log", "log.offset": 2733, "message": "2017-07-31 13:39:40.147 CEST [5502] postgres@clients LOG: duration: 0.765 ms statement: select id from clients;", @@ -206,8 +206,8 @@ }, { "@timestamp": "2017-07-31T13:40:54.310Z", - "fileset.module": "postgresql", - "fileset.name": "log", + "event.dataset": "log", + "event.module": "postgresql", "input.type": "log", "log.flags": [ "multiline" @@ -225,8 +225,8 @@ }, { "@timestamp": "2017-07-31T13:43:22.645Z", - "fileset.module": "postgresql", - "fileset.name": "log", + "event.dataset": "log", + "event.module": "postgresql", "input.type": "log", "log.offset": 3559, "message": "2017-07-31 13:43:22.645 CEST [5502] postgres@clients LOG: duration: 36.162 ms statement: create table cats(name varchar(50) primary key, toy varchar (50) not null, born timestamp not null);", @@ -241,8 +241,8 @@ }, { "@timestamp": "2017-07-31T13:46:02.670Z", - "fileset.module": "postgresql", - "fileset.name": "log", + "event.dataset": "log", + "event.module": "postgresql", "input.type": "log", "log.offset": 3751, "message": "2017-07-31 13:46:02.670 CEST [5502] postgres@c$lients LOG: duration: 10.540 ms statement: insert into cats(name, toy, born) values('kate', 'ball', now());", @@ -257,8 +257,8 @@ }, { "@timestamp": "2017-07-31T13:46:23.016Z", - "fileset.module": "postgresql", - "fileset.name": "log", + "event.dataset": "log", + "event.module": "postgresql", "input.type": "log", "log.offset": 3908, "message": "2017-07-31 13:46:23.016 CEST [5502] postgres@_clients$db LOG: duration: 5.156 ms statement: insert into cats(name, toy, born) values('frida', 'horse', now());", @@ -273,8 +273,8 @@ }, { "@timestamp": "2017-07-31T13:46:55.637Z", - "fileset.module": "postgresql", - "fileset.name": "log", + "event.dataset": "log", + "event.module": "postgresql", "input.type": "log", "log.offset": 4069, "message": "2017-07-31 13:46:55.637 CEST [5502] postgres@clients_db LOG: duration: 25.871 ms statement: create table dogs(name varchar(50) primary key, owner varchar (50) not null, born timestamp not null);", diff --git a/filebeat/module/redis/log/test/test.log-expected.json b/filebeat/module/redis/log/test/test.log-expected.json index a6eb7c0959c..514778dadfb 100644 --- a/filebeat/module/redis/log/test/test.log-expected.json +++ b/filebeat/module/redis/log/test/test.log-expected.json @@ -1,8 +1,8 @@ [ { "@timestamp": "2018-05-30T12:23:52.442Z", - "fileset.module": "redis", - "fileset.name": "log", + "event.dataset": "log", + "event.module": "redis", "input.type": "log", "log.offset": 0, "redis.log.level": "notice", @@ -12,8 +12,8 @@ }, { "@timestamp": "2018-05-30T10:05:20.000Z", - "fileset.module": "redis", - "fileset.name": "log", + "event.dataset": "log", + "event.module": "redis", "input.type": "log", "log.offset": 76, "redis.log.level": "debug", @@ -21,8 +21,8 @@ }, { "@timestamp": "2018-05-31T04:32:08.000Z", - "fileset.module": "redis", - "fileset.name": "log", + "event.dataset": "log", + "event.module": "redis", "input.type": "log", "log.offset": 165, "redis.log.level": "notice", @@ -30,8 +30,8 @@ }, { "@timestamp": "2017-05-30T10:57:24.000Z", - "fileset.module": "redis", - "fileset.name": "log", + "event.dataset": "log", + "event.module": "redis", "input.type": "log", "log.offset": 250, "redis.log.message": "Received SIGINT scheduling shutdown...", diff --git a/filebeat/module/system/auth/test/test.log-expected.json b/filebeat/module/system/auth/test/test.log-expected.json index 2fc4a94c3be..1d56b19e1da 100644 --- a/filebeat/module/system/auth/test/test.log-expected.json +++ b/filebeat/module/system/auth/test/test.log-expected.json @@ -1,8 +1,8 @@ [ { "@timestamp": "2018-02-21T21:54:44.000Z", - "fileset.module": "system", - "fileset.name": "auth", + "event.dataset": "auth", + "event.module": "system", "input.type": "log", "log.offset": 0, "system.auth.hostname": "localhost", @@ -17,8 +17,8 @@ }, { "@timestamp": "2018-02-23T00:13:35.000Z", - "fileset.module": "system", - "fileset.name": "auth", + "event.dataset": "auth", + "event.module": "system", "input.type": "log", "log.offset": 152, "system.auth.hostname": "localhost", @@ -32,8 +32,8 @@ }, { "@timestamp": "2018-02-21T21:56:12.000Z", - "fileset.module": "system", - "fileset.name": "auth", + "event.dataset": "auth", + "event.module": "system", "input.type": "log", "log.offset": 254, "system.auth.hostname": "localhost", @@ -45,8 +45,8 @@ }, { "@timestamp": "2018-02-20T08:35:22.000Z", - "fileset.module": "system", - "fileset.name": "auth", + "event.dataset": "auth", + "event.module": "system", "input.type": "log", "log.offset": 324, "system.auth.hostname": "slave22", @@ -66,8 +66,8 @@ }, { "@timestamp": "2018-02-21T23:35:33.000Z", - "fileset.module": "system", - "fileset.name": "auth", + "event.dataset": "auth", + "event.module": "system", "input.type": "log", "log.offset": 420, "system.auth.hostname": "localhost", @@ -80,8 +80,8 @@ }, { "@timestamp": "2018-02-19T15:30:04.000Z", - "fileset.module": "system", - "fileset.name": "auth", + "event.dataset": "auth", + "event.module": "system", "input.type": "log", "log.offset": 522, "system.auth.hostname": "slave22", @@ -91,8 +91,8 @@ }, { "@timestamp": "2018-02-23T00:08:48.000Z", - "fileset.module": "system", - "fileset.name": "auth", + "event.dataset": "auth", + "event.module": "system", "input.type": "log", "log.offset": 617, "system.auth.hostname": "localhost", @@ -105,8 +105,8 @@ }, { "@timestamp": "2018-02-24T00:13:02.000Z", - "fileset.module": "system", - "fileset.name": "auth", + "event.dataset": "auth", + "event.module": "system", "input.type": "log", "log.offset": 736, "system.auth.hostname": "precise32", @@ -120,8 +120,8 @@ }, { "@timestamp": "2018-02-22T11:47:05.000Z", - "fileset.module": "system", - "fileset.name": "auth", + "event.dataset": "auth", + "event.module": "system", "input.type": "log", "log.offset": 861, "system.auth.groupadd.gid": "48", @@ -132,8 +132,8 @@ }, { "@timestamp": "2018-02-22T11:47:05.000Z", - "fileset.module": "system", - "fileset.name": "auth", + "event.dataset": "auth", + "event.module": "system", "input.type": "log", "log.offset": 934, "system.auth.hostname": "localhost", diff --git a/filebeat/module/system/syslog/test/darwin-syslog-sample.log-expected.json b/filebeat/module/system/syslog/test/darwin-syslog-sample.log-expected.json index efd5e61495b..b77691a5a29 100644 --- a/filebeat/module/system/syslog/test/darwin-syslog-sample.log-expected.json +++ b/filebeat/module/system/syslog/test/darwin-syslog-sample.log-expected.json @@ -1,8 +1,8 @@ [ { "@timestamp": "2018-12-13T11:35:28.000Z", - "fileset.module": "system", - "fileset.name": "syslog", + "event.dataset": "syslog", + "event.module": "system", "input.type": "log", "log.flags": [ "multiline" @@ -16,8 +16,8 @@ }, { "@timestamp": "2018-12-13T11:35:28.000Z", - "fileset.module": "system", - "fileset.name": "syslog", + "event.dataset": "syslog", + "event.module": "system", "input.type": "log", "log.offset": 907, "system.syslog.hostname": "a-mac-with-esc-key", @@ -28,8 +28,8 @@ }, { "@timestamp": "2018-04-04T03:39:57.000Z", - "fileset.module": "system", - "fileset.name": "syslog", + "event.dataset": "syslog", + "event.module": "system", "input.type": "log", "log.offset": 1176, "system.syslog.message": "--- last message repeated 1 time ---", diff --git a/filebeat/module/traefik/access/test/test.log-expected.json b/filebeat/module/traefik/access/test/test.log-expected.json index 98f3e4c8e24..2f95d4ad9b1 100644 --- a/filebeat/module/traefik/access/test/test.log-expected.json +++ b/filebeat/module/traefik/access/test/test.log-expected.json @@ -1,8 +1,8 @@ [ { "@timestamp": "2017-10-02T20:22:07.000Z", - "fileset.module": "traefik", - "fileset.name": "access", + "event.dataset": "access", + "event.module": "traefik", "input.type": "log", "log.offset": 0, "traefik.access.body_sent.bytes": "0", @@ -24,8 +24,8 @@ }, { "@timestamp": "2017-10-02T20:22:08.000Z", - "fileset.module": "traefik", - "fileset.name": "access", + "event.dataset": "access", + "event.module": "traefik", "input.type": "log", "log.offset": 280, "traefik.access.body_sent.bytes": "0", diff --git a/filebeat/tests/system/test_modules.py b/filebeat/tests/system/test_modules.py index 7b55fe24e33..bdbd310780f 100644 --- a/filebeat/tests/system/test_modules.py +++ b/filebeat/tests/system/test_modules.py @@ -133,8 +133,8 @@ def run_on_file(self, module, fileset, test_file, cfgfile): objects = [o["_source"] for o in res["hits"]["hits"]] assert len(objects) > 0 for obj in objects: - assert obj["fileset"]["module"] == module, "expected fileset.module={} but got {}".format( - module, obj["fileset"]["module"]) + assert obj["event"]["module"] == module, "expected event.module={} but got {}".format( + module, obj["event"]["module"]) assert "error" not in obj, "not error expected but got: {}".format( obj) @@ -176,7 +176,7 @@ def _test_expected_events(self, test_file, objects): clean_keys(obj) # Remove timestamp for comparison where timestamp is not part of the log line - if obj["fileset.module"] == "icinga" and obj["fileset.name"] == "startup": + if obj["event.module"] == "icinga" and obj["event.dataset"] == "startup": delete_key(obj, "@timestamp") delete_key(ev, "@timestamp") diff --git a/x-pack/filebeat/module/suricata/eve/test/eve-alerts.log-expected.json b/x-pack/filebeat/module/suricata/eve/test/eve-alerts.log-expected.json index 2fdda9db589..faca8e538da 100644 --- a/x-pack/filebeat/module/suricata/eve/test/eve-alerts.log-expected.json +++ b/x-pack/filebeat/module/suricata/eve/test/eve-alerts.log-expected.json @@ -10,9 +10,9 @@ "destination.geo.region_name": "Massachusetts", "destination.ip": "93.184.216.34", "destination.port": 80, + "event.dataset": "eve", + "event.module": "suricata", "event.type": "alert", - "fileset.module": "suricata", - "fileset.name": "eve", "http.request.method": "GET", "http.response.status_code": "200", "input.type": "log", @@ -73,9 +73,9 @@ "destination.geo.region_name": "Massachusetts", "destination.ip": "93.184.216.34", "destination.port": 80, + "event.dataset": "eve", + "event.module": "suricata", "event.type": "alert", - "fileset.module": "suricata", - "fileset.name": "eve", "http.request.method": "GET", "http.response.status_code": "200", "input.type": "log", @@ -136,9 +136,9 @@ "destination.geo.region_name": "Massachusetts", "destination.ip": "93.184.216.34", "destination.port": 80, + "event.dataset": "eve", + "event.module": "suricata", "event.type": "alert", - "fileset.module": "suricata", - "fileset.name": "eve", "http.request.method": "GET", "http.response.status_code": "200", "input.type": "log", @@ -199,9 +199,9 @@ "destination.geo.region_name": "Massachusetts", "destination.ip": "93.184.216.34", "destination.port": 80, + "event.dataset": "eve", + "event.module": "suricata", "event.type": "alert", - "fileset.module": "suricata", - "fileset.name": "eve", "http.request.method": "GET", "http.response.status_code": "200", "input.type": "log", @@ -262,9 +262,9 @@ "destination.geo.region_name": "Massachusetts", "destination.ip": "93.184.216.34", "destination.port": 80, + "event.dataset": "eve", + "event.module": "suricata", "event.type": "alert", - "fileset.module": "suricata", - "fileset.name": "eve", "http.request.method": "GET", "http.response.status_code": "200", "input.type": "log", @@ -325,9 +325,9 @@ "destination.geo.region_name": "Massachusetts", "destination.ip": "93.184.216.34", "destination.port": 80, + "event.dataset": "eve", + "event.module": "suricata", "event.type": "alert", - "fileset.module": "suricata", - "fileset.name": "eve", "http.request.method": "GET", "http.response.status_code": "200", "input.type": "log", @@ -388,9 +388,9 @@ "destination.geo.region_name": "England", "destination.ip": "91.189.88.152", "destination.port": 80, + "event.dataset": "eve", + "event.module": "suricata", "event.type": "alert", - "fileset.module": "suricata", - "fileset.name": "eve", "http.request.method": "GET", "http.response.status_code": "200", "input.type": "log", @@ -449,9 +449,9 @@ "destination.geo.region_name": "Massachusetts", "destination.ip": "91.189.91.23", "destination.port": 80, + "event.dataset": "eve", + "event.module": "suricata", "event.type": "alert", - "fileset.module": "suricata", - "fileset.name": "eve", "http.request.method": "GET", "http.response.status_code": "304", "input.type": "log", @@ -510,9 +510,9 @@ "destination.geo.region_name": "Massachusetts", "destination.ip": "91.189.91.23", "destination.port": 80, + "event.dataset": "eve", + "event.module": "suricata", "event.type": "alert", - "fileset.module": "suricata", - "fileset.name": "eve", "http.request.method": "GET", "http.response.status_code": "200", "input.type": "log", @@ -571,9 +571,9 @@ "destination.geo.region_name": "England", "destination.ip": "91.189.88.152", "destination.port": 80, + "event.dataset": "eve", + "event.module": "suricata", "event.type": "alert", - "fileset.module": "suricata", - "fileset.name": "eve", "http.request.method": "GET", "http.response.status_code": "200", "input.type": "log", @@ -632,9 +632,9 @@ "destination.geo.region_name": "England", "destination.ip": "91.189.88.152", "destination.port": 80, + "event.dataset": "eve", + "event.module": "suricata", "event.type": "alert", - "fileset.module": "suricata", - "fileset.name": "eve", "http.request.method": "GET", "http.response.status_code": "200", "input.type": "log", @@ -693,9 +693,9 @@ "destination.geo.region_name": "England", "destination.ip": "91.189.88.152", "destination.port": 80, + "event.dataset": "eve", + "event.module": "suricata", "event.type": "alert", - "fileset.module": "suricata", - "fileset.name": "eve", "http.request.method": "GET", "http.response.status_code": "200", "input.type": "log", @@ -754,9 +754,9 @@ "destination.geo.region_name": "Massachusetts", "destination.ip": "91.189.91.23", "destination.port": 80, + "event.dataset": "eve", + "event.module": "suricata", "event.type": "alert", - "fileset.module": "suricata", - "fileset.name": "eve", "http.request.method": "GET", "http.response.status_code": "200", "input.type": "log", @@ -815,9 +815,9 @@ "destination.geo.region_name": "Massachusetts", "destination.ip": "91.189.91.23", "destination.port": 80, + "event.dataset": "eve", + "event.module": "suricata", "event.type": "alert", - "fileset.module": "suricata", - "fileset.name": "eve", "http.request.method": "GET", "http.response.status_code": "200", "input.type": "log", @@ -876,9 +876,9 @@ "destination.geo.region_name": "Massachusetts", "destination.ip": "91.189.91.23", "destination.port": 80, + "event.dataset": "eve", + "event.module": "suricata", "event.type": "alert", - "fileset.module": "suricata", - "fileset.name": "eve", "http.request.method": "GET", "http.response.status_code": "200", "input.type": "log", @@ -937,9 +937,9 @@ "destination.geo.region_name": "Massachusetts", "destination.ip": "91.189.91.23", "destination.port": 80, + "event.dataset": "eve", + "event.module": "suricata", "event.type": "alert", - "fileset.module": "suricata", - "fileset.name": "eve", "http.request.method": "GET", "http.response.status_code": "200", "input.type": "log", @@ -998,9 +998,9 @@ "destination.geo.region_name": "Massachusetts", "destination.ip": "91.189.91.23", "destination.port": 80, + "event.dataset": "eve", + "event.module": "suricata", "event.type": "alert", - "fileset.module": "suricata", - "fileset.name": "eve", "http.request.method": "GET", "http.response.status_code": "200", "input.type": "log", @@ -1059,9 +1059,9 @@ "destination.geo.region_name": "Massachusetts", "destination.ip": "91.189.91.23", "destination.port": 80, + "event.dataset": "eve", + "event.module": "suricata", "event.type": "alert", - "fileset.module": "suricata", - "fileset.name": "eve", "http.request.method": "GET", "http.response.status_code": "200", "input.type": "log", @@ -1120,9 +1120,9 @@ "destination.geo.region_name": "Massachusetts", "destination.ip": "91.189.91.23", "destination.port": 80, + "event.dataset": "eve", + "event.module": "suricata", "event.type": "alert", - "fileset.module": "suricata", - "fileset.name": "eve", "http.request.method": "GET", "input.type": "log", "log.offset": 14767, @@ -1179,9 +1179,9 @@ "destination.geo.region_name": "Massachusetts", "destination.ip": "91.189.91.23", "destination.port": 80, + "event.dataset": "eve", + "event.module": "suricata", "event.type": "alert", - "fileset.module": "suricata", - "fileset.name": "eve", "http.request.method": "GET", "input.type": "log", "log.offset": 15651, diff --git a/x-pack/filebeat/module/suricata/eve/test/eve-small.log-expected.json b/x-pack/filebeat/module/suricata/eve/test/eve-small.log-expected.json index 89a8c53cffc..fe378f89a9b 100644 --- a/x-pack/filebeat/module/suricata/eve/test/eve-small.log-expected.json +++ b/x-pack/filebeat/module/suricata/eve/test/eve-small.log-expected.json @@ -3,9 +3,9 @@ "@timestamp": "2018-07-05T19:01:09.820Z", "destination.ip": "192.168.253.112", "destination.port": 22, + "event.dataset": "eve", + "event.module": "suricata", "event.type": "ssh", - "fileset.module": "suricata", - "fileset.name": "eve", "input.type": "log", "log.offset": 0, "source_ecs.ip": "192.168.86.85", @@ -31,9 +31,9 @@ "@timestamp": "2018-07-05T19:07:20.910Z", "destination.ip": "192.168.156.70", "destination.port": 443, + "event.dataset": "eve", + "event.module": "suricata", "event.type": "alert", - "fileset.module": "suricata", - "fileset.name": "eve", "input.type": "log", "log.offset": 350, "source_ecs.ip": "192.168.86.85", @@ -72,9 +72,9 @@ "@timestamp": "2018-07-05T19:43:47.690Z", "destination.ip": "192.168.86.28", "destination.port": 63963, + "event.dataset": "eve", + "event.module": "suricata", "event.type": "http", - "fileset.module": "suricata", - "fileset.name": "eve", "http.request.method": "GET", "http.response.status_code": "200", "input.type": "log", @@ -117,11 +117,11 @@ "@timestamp": "2018-07-05T19:44:33.222Z", "destination.ip": "192.168.86.85", "destination.port": 56118, + "event.dataset": "eve", + "event.module": "suricata", "event.type": "fileinfo", "file.path": "/ssdp/device-desc.xml", "file.size": 1071, - "fileset.module": "suricata", - "fileset.name": "eve", "http.request.method": "GET", "http.response.status_code": "200", "input.type": "log", @@ -173,9 +173,9 @@ "@timestamp": "2018-07-05T19:51:20.213Z", "destination.ip": "192.168.86.85", "destination.port": 39464, + "event.dataset": "eve", + "event.module": "suricata", "event.type": "dns", - "fileset.module": "suricata", - "fileset.name": "eve", "input.type": "log", "log.offset": 2347, "source_ecs.ip": "192.168.86.1", @@ -202,9 +202,9 @@ }, { "@timestamp": "2018-07-05T19:51:23.009Z", + "event.dataset": "eve", + "event.module": "suricata", "event.type": "stats", - "fileset.module": "suricata", - "fileset.name": "eve", "input.type": "log", "log.offset": 2687, "suricata.eve.event_type": "stats", @@ -337,9 +337,9 @@ "destination.geo.location.lon": -97.822, "destination.ip": "17.142.164.13", "destination.port": 443, + "event.dataset": "eve", + "event.module": "suricata", "event.type": "tls", - "fileset.module": "suricata", - "fileset.name": "eve", "input.type": "log", "log.offset": 4683, "source_ecs.ip": "192.168.86.85", @@ -369,9 +369,9 @@ "@timestamp": "2018-07-05T19:51:54.001Z", "destination.ip": "ff02:0000:0000:0000:0000:0000:0001:0002", "destination.port": 547, + "event.dataset": "eve", + "event.module": "suricata", "event.type": "flow", - "fileset.module": "suricata", - "fileset.name": "eve", "input.type": "log", "log.offset": 5308, "source_ecs.ip": "fe80:0000:0000:0000:fada:0cff:fedc:87f1",