Hi,
I am trying to use logstash to create a field of dns.type based on the types within dns.answers. This is from event.code 22 from sysmon.
i have tried:
if "AAAA" in [dns][answers] {
mutate {
add_field => {"[dns][type]" => "AAAA"}
}
}
also tried KV with no joy.
Any suggestions
dns.answers
{
"type": "AAAA",
"data": "2a04:4e42::81"
},
{
"type": "AAAA",
"data": "2a04:4e42:200::81"
},
{
"type": "AAAA",
"data": "2a04:4e42:400::81"
},
{
"type": "AAAA",
"data": "2a04:4e42:600::81"
},
{
"type": "A",
"data": "151.101.64.81"
},
{
"type": "A",
"data": "151.101.128.81"
},
{
"type": "A",
"data": "151.101.192.81"
},
{
"type": "A",
"data": "151.101.0.81"
}