Skip to content

Commit c6ca6af

Browse files
committed
Add convert for inode field
1 parent 15c9c6b commit c6ca6af

File tree

8 files changed

+24
-4
lines changed

8 files changed

+24
-4
lines changed

‎packages/microsoft_exchange_server/data_stream/httpproxy/elasticsearch/ingest_pipeline/default.yml‎

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -272,6 +272,11 @@ processors:
272272
type: long
273273
ignore_failure: true
274274
ignore_missing: true
275+
- convert:
276+
field: "log.file.inode"
277+
type: long
278+
ignore_failure: true
279+
ignore_missing: true
275280
- set:
276281
field: event.ingested
277282
copy_from: _ingest.timestamp

‎packages/microsoft_exchange_server/data_stream/httpproxy/fields/fields.yml‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -141,6 +141,6 @@
141141
- name: log.file.device_id
142142
type: keyword
143143
- name: log.file.inode
144-
type: keyword
144+
type: long
145145
- name: log.offset
146146
type: long

‎packages/microsoft_exchange_server/data_stream/imap4_pop3/elasticsearch/ingest_pipeline/default.yml‎

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -59,6 +59,11 @@ processors:
5959
field: microsoft.exchange.seqnumber
6060
type: long
6161
ignore_failure: true
62+
- convert:
63+
field: "log.file.inode"
64+
type: long
65+
ignore_failure: true
66+
ignore_missing: true
6267
- set:
6368
field: event.ingested
6469
copy_from: _ingest.timestamp

‎packages/microsoft_exchange_server/data_stream/imap4_pop3/fields/fields.yml‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -29,6 +29,6 @@
2929
- name: log.file.device_id
3030
type: keyword
3131
- name: log.file.inode
32-
type: keyword
32+
type: long
3333
- name: log.offset
3434
type: long

‎packages/microsoft_exchange_server/data_stream/messagetracking/elasticsearch/ingest_pipeline/default.yml‎

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -68,6 +68,11 @@ processors:
6868
type: long
6969
ignore_failure: true
7070
ignore_missing: true
71+
- convert:
72+
field: "log.file.inode"
73+
type: long
74+
ignore_failure: true
75+
ignore_missing: true
7176
- set:
7277
field: event.ingested
7378
value: "{{{_ingest.timestamp}}}"

‎packages/microsoft_exchange_server/data_stream/messagetracking/fields/fields.yml‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -41,6 +41,6 @@
4141
- name: log.file.device_id
4242
type: keyword
4343
- name: log.file.inode
44-
type: keyword
44+
type: long
4545
- name: log.offset
4646
type: long

‎packages/microsoft_exchange_server/data_stream/smtp/elasticsearch/ingest_pipeline/default.yml‎

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -36,6 +36,11 @@ processors:
3636
field: microsoft.exchange.sequencenumber
3737
type: long
3838
ignore_failure: true
39+
- convert:
40+
field: "log.file.inode"
41+
type: long
42+
ignore_failure: true
43+
ignore_missing: true
3944
- set:
4045
field: event.ingested
4146
copy_from: _ingest.timestamp

‎packages/microsoft_exchange_server/data_stream/smtp/fields/fields.yml‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -21,6 +21,6 @@
2121
- name: log.file.device_id
2222
type: keyword
2323
- name: log.file.inode
24-
type: keyword
24+
type: long
2525
- name: log.offset
2626
type: long

0 commit comments

Comments
 (0)