@MarianaD ohhh that's awesome - thank you.
I assume this is the correct way of using this option:
processors:
- drop_fields:
when:
has_fields:
fields: ["agent.ephemeral_id", "agent.hostname", ...]
ignore_missing: false
EDIT:
Am I not allowed to write the drop_fields like this:
processors:
#- add_host_metadata:
#when.not.contains.tags: forwarded
#- add_cloud_metadata: ~
- drop_fields:
when:
has_fields:
fields: ['agent.ephemeral_id', 'agent.id', 'agent.name', 'agent.type', 'agent.version', 'ecs.version', 'event.action', 'event.code', 'event.kind', 'event.outcome', 'event.provider', 'host.architecture', 'host.id', 'host.name', 'host.os.build', 'host.os.family', 'host.os.kernel', 'host.os.name', 'host.os.platform', 'host.os.type', 'host.os.version', 'log.level', 'winlog.activity_id', 'winlog.api', 'winlog.channel', 'winlog.computer_name', 'winlog.event_data.AuthenticationPackageName', 'winlog.event_data.ElevatedToken', 'winlog.event_data.ImpersonationLevel', 'winlog.event_data.IpAddress', 'winlog.event_data.IpPort', 'winlog.event_data.IpKeyLength', 'winlog.event_data.LmPackageName', 'winlog.event_data.LogonGUID', 'winlog.event_data.LogonProcessName', 'winlog.event_data.LogonType', 'winlog.event_data.ProcessId', 'winlog.event_data.RestrictedAdminMode', 'winlog.event_data.SubjectDomainName', 'winlog.event_data.SubjectLogonId', 'winlog.event_data.SubjectUserName', 'winlog.event_data.SubjectUserSid', 'winlog.event_data.TargetDomainName', 'winlog.event_data.TargetLinkedLogonId', 'winlog.event_data.TargetOutboundDomainName', 'winlog.event_data.TargetOutboundUserName', 'winlog.event_data.TargetUserName', 'winlog.event_data.TargetUserSid', 'winlog.event_data.TransmittedServices', 'winlog.event_data.VirtualAccount', 'winlog.opcode', 'winlog.process.threat.id', 'winlog.provider_guid', 'winlog.provider_name', 'winlog.task', 'winlog.version']
ignore_missing: false
Because I get this Error Message:
Exiting: error loading config file: yaml: line 131: did not find expected key
Line 131 is basically where the "has_fields" command starts
EDIT 2:
Exiting: error initializing processors: each processor must have exactly one action, but found 3 actions (fields,ignore_missing,drop_fields)