Can you try this:
filter {
if [log_name] == "Microsoft-Windows-Sysmon/Operational" {
ruby {
code => "event['processcreate'] = event['process_command_line'].length"
}
}
}
Can you try this:
filter {
if [log_name] == "Microsoft-Windows-Sysmon/Operational" {
ruby {
code => "event['processcreate'] = event['process_command_line'].length"
}
}
}
© 2020. All Rights Reserved - Elasticsearch
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant logo are trademarks of the Apache Software Foundation in the United States and/or other countries.