|
| 1 | +{ |
| 2 | + "description" : " Email alerts from Sublime", |
| 3 | + "processors" : [ |
| 4 | + { "set": { "field": "event.module", "value": "sublime" } }, |
| 5 | + { "set": { "field": "event.dataset", "value": "alert" } }, |
| 6 | + { "set": { "field": "event.severity", "value": 3, "override": true } }, |
| 7 | + { "set": { "field": "rule.name", "value": "Sublime Platform: {{ flagged_rules.0.name }}", "override": true } }, |
| 8 | + { "set": { "field": "sublime.message_group_id", "value": "{{ _id }}", "override": true } }, |
| 9 | + { "set": { "field": "email.address", "value": "{{ messages.0.recipients.0.email }}", "override": true } }, |
| 10 | + { "set": { "field": "email.forwarded_recipents", "value": "{{ messages.0.forwarded_receipients }}", "override": true } }, |
| 11 | + { "set": { "field": "email.sender.address", "value": "{{ messages.0.sender.email }}", "override": true } }, |
| 12 | + { "set": { "field": "email.subject", "value": "{{ messages.0.subject }}", "override": true } }, |
| 13 | + { "set": { "field": "email.forwarded_at", "value": "{{ messages.0.forwarded_at }}", "override": true } }, |
| 14 | + { "set": { "field": "email.created_at", "value": "{{ messages.0.created_at }}", "override": true } }, |
| 15 | + { "set": { "field": "email.read_at", "value": "{{ messages.0.read_at }}", "override": true } }, |
| 16 | + { "set": { "field": "email.replied_at", "value": "{{ messages.0.replied_at }}", "override": true } }, |
| 17 | + { |
| 18 | + "grok": { |
| 19 | + "field": "sublime.request_url", |
| 20 | + "patterns": ["^https://api.%{DATA:sublime_host}/v0%{GREEDYDATA}$"], |
| 21 | + "ignore_failure": true |
| 22 | + } |
| 23 | + }, |
| 24 | + |
| 25 | + { "rename": { "field": "sublime_host", "target_field": "sublime.url", "ignore_missing": true } }, |
| 26 | + { "rename": { "field": "data", "target_field": "sublime", "ignore_missing": true } }, |
| 27 | + { "rename": { "field": "flagged_rules", "target_field": "sublime.flagged_rules", "ignore_missing": true } }, |
| 28 | + { "rename": { "field": "organization_id", "target_field": "sublime.organization_id", "ignore_missing": true } }, |
| 29 | + { "rename": { "field": "review_status", "target_field": "sublime.review_status", "ignore_missing": true } }, |
| 30 | + { "rename": { "field": "state", "target_field": "sublime.state", "ignore_missing": true } }, |
| 31 | + { "rename": { "field": "user_reports", "target_field": "sublime.user_reports", "ignore_missing": true } }, |
| 32 | + { "pipeline": { "name": "common" } } |
| 33 | + ] |
| 34 | +} |
0 commit comments