diff --git a/CHANGELOG.next.asciidoc b/CHANGELOG.next.asciidoc index ffc9672f554..914324833c5 100644 --- a/CHANGELOG.next.asciidoc +++ b/CHANGELOG.next.asciidoc @@ -107,6 +107,7 @@ https://github.com/elastic/beats/compare/v7.0.0-alpha2...master[Check the HEAD d - Change logging in logs input to structure logging. Some log message formats have changed. {pull}25299[25299] - Change source field for `event.action` in `fortinet.firewall` module to `fortinet.firewall.action` instead of `fortinet.firewall.eventtype`. {pull}24816[24816] - threatintel module: Changed the type of `threatintel.indicator.first_seen` from `keyword` to `date`. {pull}26765[26765] +- Remove all alias fields pointing to ECS fields from modules. This affects the Suricata and Traefik modules. {issue}10535[10535] {pull}26627[26627] *Heartbeat* - Add support for screenshot blocks and use newer synthetics flags that only works in newer synthetics betas. {pull}25808[25808] diff --git a/filebeat/docs/fields.asciidoc b/filebeat/docs/fields.asciidoc index 51e92cafff2..5e88e7653be 100644 --- a/filebeat/docs/fields.asciidoc +++ b/filebeat/docs/fields.asciidoc @@ -150119,15 +150119,6 @@ type: keyword -- -*`suricata.eve.fileinfo.filename`*:: -+ --- -type: alias - -alias to: file.path - --- - *`suricata.eve.fileinfo.tx_id`*:: + -- @@ -150170,15 +150161,6 @@ type: keyword -- -*`suricata.eve.fileinfo.size`*:: -+ --- -type: alias - -alias to: file.size - --- - *`suricata.eve.icmp_type`*:: + -- @@ -150186,33 +150168,6 @@ type: long -- -*`suricata.eve.dest_port`*:: -+ --- -type: alias - -alias to: destination.port - --- - -*`suricata.eve.src_port`*:: -+ --- -type: alias - -alias to: source.port - --- - -*`suricata.eve.proto`*:: -+ --- -type: alias - -alias to: network.transport - --- - *`suricata.eve.pcap_cnt`*:: + -- @@ -150220,15 +150175,6 @@ type: long -- -*`suricata.eve.src_ip`*:: -+ --- -type: alias - -alias to: source.ip - --- - *`suricata.eve.dns.type`*:: + @@ -150301,15 +150247,6 @@ type: keyword -- -*`suricata.eve.dest_ip`*:: -+ --- -type: alias - -alias to: destination.ip - --- - *`suricata.eve.icmp_code`*:: + -- @@ -150318,15 +150255,6 @@ type: long -- -*`suricata.eve.http.status`*:: -+ --- -type: alias - -alias to: http.response.status_code - --- - *`suricata.eve.http.redirect`*:: + -- @@ -150334,15 +150262,6 @@ type: keyword -- -*`suricata.eve.http.http_user_agent`*:: -+ --- -type: alias - -alias to: user_agent.original - --- - *`suricata.eve.http.protocol`*:: + -- @@ -150350,51 +150269,6 @@ type: keyword -- -*`suricata.eve.http.http_refer`*:: -+ --- -type: alias - -alias to: http.request.referrer - --- - -*`suricata.eve.http.url`*:: -+ --- -type: alias - -alias to: url.original - --- - -*`suricata.eve.http.hostname`*:: -+ --- -type: alias - -alias to: url.domain - --- - -*`suricata.eve.http.length`*:: -+ --- -type: alias - -alias to: http.response.body.bytes - --- - -*`suricata.eve.http.http_method`*:: -+ --- -type: alias - -alias to: http.request.method - --- - *`suricata.eve.http.http_content_type`*:: + -- @@ -150426,15 +150300,6 @@ type: keyword -- -*`suricata.eve.alert.severity`*:: -+ --- -type: alias - -alias to: event.severity - --- - *`suricata.eve.alert.rev`*:: + -- @@ -150456,15 +150321,6 @@ type: keyword -- -*`suricata.eve.alert.action`*:: -+ --- -type: alias - -alias to: event.outcome - --- - *`suricata.eve.alert.signature_id`*:: + -- @@ -151611,33 +151467,6 @@ type: keyword -- -*`suricata.eve.flow.bytes_toclient`*:: -+ --- -type: alias - -alias to: destination.bytes - --- - -*`suricata.eve.flow.start`*:: -+ --- -type: alias - -alias to: event.start - --- - -*`suricata.eve.flow.pkts_toclient`*:: -+ --- -type: alias - -alias to: destination.packets - --- - *`suricata.eve.flow.age`*:: + -- @@ -151652,15 +151481,6 @@ type: keyword -- -*`suricata.eve.flow.bytes_toserver`*:: -+ --- -type: alias - -alias to: source.bytes - --- - *`suricata.eve.flow.reason`*:: + -- @@ -151668,15 +151488,6 @@ type: keyword -- -*`suricata.eve.flow.pkts_toserver`*:: -+ --- -type: alias - -alias to: source.packets - --- - *`suricata.eve.flow.alerted`*:: + -- @@ -151684,15 +151495,6 @@ type: boolean -- -*`suricata.eve.app_proto`*:: -+ --- -type: alias - -alias to: network.protocol - --- - *`suricata.eve.tx_id`*:: + -- @@ -159585,15 +159387,6 @@ alias to: user_agent.original -- -*`traefik.access.user_agent.device`*:: -+ --- -type: alias - -alias to: user_agent.device.name - --- - *`traefik.access.user_agent.name`*:: + -- diff --git a/filebeat/module/traefik/access/_meta/fields.yml b/filebeat/module/traefik/access/_meta/fields.yml index 4cf03cfaf24..36cb2cb586e 100644 --- a/filebeat/module/traefik/access/_meta/fields.yml +++ b/filebeat/module/traefik/access/_meta/fields.yml @@ -60,9 +60,6 @@ - name: user_agent type: group fields: - - name: device - type: alias - path: user_agent.device.name - name: name type: alias path: user_agent.name diff --git a/filebeat/module/traefik/fields.go b/filebeat/module/traefik/fields.go index f7e75e94d57..089f032fecc 100644 --- a/filebeat/module/traefik/fields.go +++ b/filebeat/module/traefik/fields.go @@ -32,5 +32,5 @@ func init() { // AssetTraefik returns asset data. // This is the base64 encoded gzipped contents of module/traefik. func AssetTraefik() string { - return "eJyslb9upDAQxvt9ilH6IEV31RbXRIp0xTWn9MjBA2ut8XDjcSLe/mR2SQiyCZB1t3jn+33zx/Y9nLE/grDC2pwPAGLE4hHuni9f7g4AGn3FphND7gi/DgAAf0gHi1ATQ6fYG9eAnBCuQWCpgdpY9MUBoDZotT8OcffgVItTXlzSd3iEhil01y8JZFxPgxTUTG2eF9eUOeWqqkLv3z+n0Av4uB7JiTLOXxFDCaZWLoTo6N1MytDUVPDIpdHoxNQG+dN/Rodn7N+I9WxvwWdcv/1g7e/TIzz8fPgBF4b0QPWwUVmDTpKeGP8F9FJWFGb/GB1Zcs02O88nBBfaF+Ro4ErwSXzN5ASdLuPP2xVkcKBaHAswYmILdNLIi6rO0Udgu9NG0kRgO3q4EuDthIxjVcAMk/WmWE+MpR2S7kuPToqXXtAnXSpr1HynU3I6wkmkKxh9R85jEbWSMq1pWF2qKhwwMzItCZam22jBU+AKC6U1fz6ba8HD+ckOSh4c44pE3Bpmi3KiedtXFnvocJFUWJVuZhQXEmVbEJvGODUPXQOMtstXZG/I7ck4HbpupC6DWVakt3b382R7URJ8SmedjxqZM1fzyn5nNNbgVTO/ptcNdzkEbm19/ozlfcwfUMg8eVNJja+mmndjObVkehed1EH+YCU3N5MWEZSS2AggX9TB2tRlNgWl9/fQlkHpudlDmislZ6xByjwee8arIifGoZPvVOv6NjVIxRd6H9jghPvSeErdNrvAXyiOaEvVcJ6/j8wqfVyIjSF3o8ouib2X1Uh/q0ZmpWbZ3a6FOcHD/wAAAP//R4Rz0Q==" + return "eJyslTFv4zwMhvf8CqJ7DRTfN2W4pUCBG245dDdUi3aEyKKPoq7wvz/IsVvHkFzHjbZY4fu8IinqEc7YH0FYYW3OBwAxYvEID6+XLw8HAI2+YtOJIXeEHwcAgF+kg0WoiaFT7I1rQE4IYxBYaqA2Fn1xAKgNWu2PQ9wjONXinBeX9B0eoWEK3fglgYzrZZCCmqnN8+KaM+dcVVXo/cfnFHoFH9czOVHG+RExpGBu5UKIjj7MpAzNTQWPXBqNTkxtkK/+Mzk8Y/9OrBd7Kz7j+ukHa79fnuHp/6f/4MKQHqgeNipr0EnSE+OfgF7KisLiH5MjS665zc7rCcGF9g05GhgJPomvmZyg02X8eb+EDA5Ui1MCJkwsgU4aeVPVOfoIbHfaSJoIbCcPIwHeT8g4ZQXM0FnvivXMWNoh6b706KR46wV90qWyRi13OiWnI5xEuoLRd+Q8FlErKdOahtUlq8IBMy3TkmBpuhsteApcYaG05uu7uRU83J9so+TBMa5IxG1htignWpZ9Y7KHChdJhU3HzbTiykHZFsSmMU4tQ7cAo+3yL7I35PacOB26raUujVlWpG+t7nVne1ESfEpnm48amTOjeWO9Mxpb8KpZjultzV0OgbeWPn/H8j6WDyhknry5ZOLmrR8sebikyoSglMSNAPJFHaxNDZg5KL2/h7YOStdyD2mplKx7g5QZ6HtKXpET49DJd7I1vhcNUvGF3ic2OOG+NJ5SE2AX+AvFCW2pGu7Y95FZpc8h1Rhyd8rsmthHWo309ypkVmpxuvuVMCd4+BcAAP//8XRZtA==" } diff --git a/x-pack/filebeat/module/suricata/eve/_meta/fields.yml b/x-pack/filebeat/module/suricata/eve/_meta/fields.yml index aea9bd35c4f..ffd82f2e448 100644 --- a/x-pack/filebeat/module/suricata/eve/_meta/fields.yml +++ b/x-pack/filebeat/module/suricata/eve/_meta/fields.yml @@ -45,10 +45,6 @@ - name: sha1 type: keyword - - name: filename - type: alias - path: file.path - - name: tx_id type: long @@ -67,32 +63,12 @@ - name: md5 type: keyword - - name: size - type: alias - path: file.size - - name: icmp_type type: long - - name: dest_port - type: alias - path: destination.port - - - name: src_port - type: alias - path: source.port - - - name: proto - type: alias - path: network.transport - - name: pcap_cnt type: long - - name: src_ip - type: alias - path: source.ip - - name: dns type: group fields: @@ -129,50 +105,18 @@ - name: status type: keyword - - name: dest_ip - type: alias - path: destination.ip - - name: icmp_code type: long - name: http type: group fields: - - name: status - type: alias - path: http.response.status_code - - name: redirect type: keyword - - name: http_user_agent - type: alias - path: user_agent.original - - name: protocol type: keyword - - name: http_refer - type: alias - path: http.request.referrer - - - name: url - type: alias - path: url.original - - - name: hostname - type: alias - path: url.domain - - - name: length - type: alias - path: http.response.body.bytes - - - name: http_method - type: alias - path: http.request.method - - name: http_content_type type: keyword @@ -189,10 +133,6 @@ - name: category type: keyword - - name: severity - type: alias - path: event.severity - - name: rev type: long @@ -202,10 +142,6 @@ - name: signature type: keyword - - name: action - type: alias - path: event.outcome - - name: signature_id type: long - name: protocols @@ -739,42 +675,18 @@ - name: flow type: group fields: - - name: bytes_toclient - type: alias - path: destination.bytes - - - name: start - type: alias - path: event.start - - - name: pkts_toclient - type: alias - path: destination.packets - - name: age type: long - name: state type: keyword - - name: bytes_toserver - type: alias - path: source.bytes - - name: reason type: keyword - - name: pkts_toserver - type: alias - path: source.packets - - name: alerted type: boolean - - name: app_proto - type: alias - path: network.protocol - - name: tx_id type: long diff --git a/x-pack/filebeat/module/suricata/fields.go b/x-pack/filebeat/module/suricata/fields.go index bf4b172bdf0..4a99f4e4be9 100644 --- a/x-pack/filebeat/module/suricata/fields.go +++ b/x-pack/filebeat/module/suricata/fields.go @@ -19,5 +19,5 @@ func init() { // AssetSuricata returns asset data. // This is the base64 encoded gzipped contents of module/suricata. func AssetSuricata() string { - return "eJzsXEuP4zbyv8+n0C2nGP/M/BMs+rC37GGB7B4C7JUoUyWZMV9Dltzt/fQLyW63bJEyH8IsNsmcGt3DH+vFerGo75sjnl8aPzjBgeBT05AgiS/Nrx+/adFzJywJo1+av35qmqb5xbSDxKYzrjmAbqXQfUMHbH7+18/N33/95z8aaXrfWGfagWPb7M83vN2npukEyta/TEjfNxoU3lEw/qOzxZemd2aw198EqBj//W3Cajpn1ETB+z4TKdL0TSck7q7/fb7xfHM84e13ob1X9p/RgG/WOLqwuxDGbMEjFQ+UaGIjBXd/fifqiOdX49rb34IYYC2zzpBhxom+HIe4DS5+lEyMpzsk1km4k0IyOR8w1h8iAHtjJIJ+BnCjgxGvIwX4sY4Uf9aVAAT0aCSZTMzEUakZ56mOm04UieNjuUShO7ORvfoD/FAnkJGg8acICkgBS5FboMNl6W788an63phoIxtIo/tvYEGejMMYDYmq78HGrC/1KBzg848/1XGi2h8rRSH+Xaztu7VBAxdc2XhYiGv7fX2LntgYnoLrQwReyBvXCQ1j1NvdLQ/u4h0v2cSbwXFMwJ+iWia4Rno17rgjB9onbMHBMq7DLDyX8ygBEQ6bT/mfrQvrUD8uL47HS0PKdfhuC4wVD5mK0X7kjIUQtW6USFasdty0lTIooP4WpqR5XXKfkSOiAvHIfnHUJaChKBG583LZx2/u456dwckPB1SWKvAD0VZJ9aq41kLOSMPOobdGe9xdYO55itkqtsIhj6V6ieY6bs8Gj45BjwtHm8LAx+LdWOEIDfLZplPk4CZ2UnNId9ihKxf71wE97SYQN8OJ7Di4GMmrAnIyWTIH46kwUx23aY0C8TRDk6h7ihVv6ba6N+15tz8T+iRNKaSDiTnHZFU9oKxtyI2mSP2e5ceEZqIDXtMDkBhJw/IdjUKClTDbSSBCHSgD7lomv1xRGtibgaYGyUTk7plkORD2xp0r03M8oRMUQ1mzhqkns1sARJ3kqSId6OsqOtFroMFVJhTAR5UVS8oMxI16Gk1uxCamX/er3x16ar7wwCER8CMjcD2mhrN7BA4WeZzyJ4tfV5heX6pAvkKygh+2PZWu856dPrM9+DoAQmWNg9QoHAL5UkvFlzoqrBNmxY+sLx5jrZBl1AvdIados+UJ6w6BsGUQM/Z22Qq6pSC2LV7LJXifEQ3vV7tBIrsUx0XrfeEZg+4iana5wChzEC1aac4qnuGuL++MU+hYZvC7x1CCHDIyRpZ6G4tuJAQ0RyaUhUJZfLj6J2F4HYbgMRpk5UR+cX1QmhFxKeJ6DcHFAB/iGTuh86HQmxjAZ7yajsY4UYv4kT65U7Tq+R1xPC+ut+q2cbArOVmZ8I7oNEpmgR8xcHmTkjQuwFpnAp34IijRlYN9xB0S0bI0BaBFijcrysQeKqvyiAo0gOpIUqg4LJflqU2hGgJZVQ5jnRiDNZmNDd1Y1GzErjOmFjsXjR6Fgoc3NoKyg6g+gcKe/j8KESYvTuAsYAqFZghSl0bfTL0O+jGZ2QLLIXiPai8D2Wwq2kxyy5u/PyX3/LhK87rpcSBumcNSLzJz++0GzqzeI6JC1zNlWmSoCUO33MWAJpRK5aEtZ3NyEQRXa0cnAyTuudJAvA01NL55AAuJtCq/9Ti0hnUgwqc1S0Res4tZT1larda0R0esBYLJFiXYicxaItGPiXdtLLzIrZaWsw6NaJXLSY9lsNxETIHJr29m7HPmTiBFy/gB+dEPqlr5U5Db0EqvlrmNDqXwtIXyQoNumYIih6BYi5YOzCHwQ7V3uGUFZ7aJaczw+moFvDuYVnQdC14j5eFpw4K5S141wE27cTsDTj2zR2LBObA8Fu9vOMsw6hMEB2VCnnlyW0vDSYJmX4X+WonznR6k/K4SRNKIEgUpLzYG7Qd7mR0PXx2nUjoT/ZEYGcO8giDJRbGiUn59dZa3WiZvUC8mmvVxi3r/JyY024AaYdcOarlRvucHwq50VLP9gfnvl4dt4DapXlzbHrjR79XmGTzQaMzMM+Ftq5A2VdC1Sb2ygev+TKmsOPD/tboZnbfVZoJ0QKcDQxD5nnkrh4aIf/m/zz/Acl4sK8cLFKL1fXbWS7MPjA6UdKhY+AHGt+/cS/PKVL9tOuzMq2f7wS9vevP4G4nz7NqO3QRLm23QJg79UVhbXcBxafw0bjCExugy6yN83QboIi2HypyqsfZnO5aUG7E4vWXZjsWrOTCh60vnC+LUU6kv60coBW8Sa52825goVDYwwpHjc8BaJuG8cQ2+2hiouAwKph3Z90DBfCwXJXh/XEDM1JVm4Ww6F6zVfkOkcOciF8mrLeW0DU3Kl9dQa2NMJShCBTt72Qrj6CzfSvsXsK0MYF+Mcjv4b396kz+4A9jmtP3+jkncmuPnY31MThvaYxefH7obM45gCO8HdG3s7ULqsKMWdQCxhlkeFZfrVObQD6r2kX0ndI/OOpE8jhylyonk0fm4pqGjaO6Xomg/7H+rfon4G3zJ6xG02MEgiU2GPCYHMlAwPI8AnpxYPGxZo38JcYBVv5QugD8g//Ma5DKEHBn1TUIJ1BylHnC692NkVsfL195fzV8yJz2T9ASBedbnG12fxN2tjmxhj7QZT4/jzpEtoa8ZG97gsyjvilydml9j+vpFiCQdOgRfG2uuSqqlN1U/El38JVPSB39uZzd49J5/DWTxHjyc3AQ+DZGaGM28y+O3pjK8SyCLLfUujltiC4FlGooCIVnnzHJcKAvmgLKIkKVw8c2GnsVlOfDlh8mey/g/AQAA///iW3Xg" + return "eJzsXEuPI7cRvu+v6JtPXsS7sRHMITfnEMDJwUCuRImsbtHiy2S1ZpRfH3RrRtNSk1LzgQn8mMsC0vLrj8V6s1rfdgc8PXVh9JIDwaeuI0kKn7qf3z8RGLiXjqQ1T93fP3Vd1/1kxaiw663v9mCEkmboaI/dj//5sfvnz//+V6fsEDrnrRg5im53uuB9/tR1vUQlwtOM9G1nQOMVg+mPTg6fusHb0b1+EmEx/f1jxup6b/XM4O05MxVlh66XCj+//vflg5cPxyNePos9+87zFxzwxVlP5+2uhLFYcMvihokhNjG4+vqN1AFPz9aLy3dRDHCOOW/JMuvlUI5D3EUX30omtacrJNYruJLCZjrvMC7sEwA7axWCeQRw4cGI11EBfqijEk6mEoCAbpUkcxMLcVSejA9Ut5teFonjfblCaXrbSF/DHr6rFO0LkyIBoawZPuB0A1mPKQ4bj2UAl9KMrWq6hy/f/1C3Ey2+LwF4Wy65dmmXmj6Ni9vh4Bg3txq+dbkwtyIsdqPrPeTaqW+BMf1biSHeQ30hRK2FEamK1Z5bUSmDAvYXd6fs83r3GSaBGuTt9oudJQGNRfHjykAjAt0qjj1Rq0zFo5AeeSqabU1UpuyL25SCbUSZtsW4NZRICfNkbJjsgdeklQp93Afmi1kjwR0X0CsgQhOJXldZ+E+vKB3s7Ehzzj2T/PxIshwIB+tPlU4MjxUeZKjLD+RggEZfmyO8wWz0pder39R8q/FfrwYi4AdG4Afcam/XCBwc8jTzB4uf72z6/lIN6hk2i/7mscfSdSGw4xe2g1AHQKid9bDVN8VAvtay+FrHwnlpvaSt5nu9eG8DSVXGXpoeOSWT6gdb9wiEgkFK2cU65X9bOzpRvJYrCCEjfFyv9qNCFuzoV6Fj2/pQaGPQn0XNzk2kMgch0Cl70rjK3bct763X6FlmtLjG0JI8MrJWlXobh34iAoYjk9pBoSzeXX3AIxabD8FtNMhKIsKqhVOaQnAl0+cag0sB3sQzdkQfpF23IzaG1sVebU9TnKhFvOChP6L//e94WVi0Kp05uDvZUpnwDugNKuaAHzDSQNuSzq3AhLeRjksRlOzLwd7jDslkrb8FQCClq6kyscfqkDxSkXqxjpJGzWG9LO/YNOoxklXlbKyXU7Am21jRrUPDJuw6ZRLY+2T0KBQ8vLAJlO1ltQVKd/xrEiJOL01wETClRjtG2W3jtzheD8OUzLTA8gghoN6pSDa7FW0huXWH90/JPTZXZZ+bmgNxxzyWepGF2xcNnFm9R0SNfmDaCmRoCGO3GcWANpZK5aGt70dzESTX90wnAyTtubaBBBdraHx4AIuJtCq/DTgKy3qQcWvNElEw7KzWc5ZWe2omoCcmgGDWRQVupllLEsOUeNfGwrPcarmcTOyavFxOZiqDVRMxRW7fP0zZl5s7gpKC8T3yQxh19eHPQa6hlr5qZpszVDJQi8OLDRtkCoo8gmYCHe2ZR+D7au9wyQpOrIlqLPCG6gN4czBC9j2L3rvk4RnLorlLXjXArWjczoDjwNyBWJD/rZX/7kSF5U7LBMFDmZAXntzVcjgqMOxXaX6txPnGjEp9UwmiaEJJgpQXG6MJozvP78XvWrcyXYj+QIysZUFDlHJRrKiU31Cd5d0tkxvUixvV+tCi3v+BScMasJHunqGWK+VbfiDdnY5qtj+w///yUERuk+rF1dbgJr9Xm2fwSKMxM8+El1Yhba6ga5N67SLX/ZlSuePAf2t1M/rgqtUEaY/eRIYg8j1zK4eGiH/7y5fvYD1wnZXjRQrR+j47G5TdRUYHSjpULD5o+/Gde2WfmR7apsPePge2G8P6pjdvfxO5wF7bsU2wjG2DNu8wHKRz1QUcVzbM4wZjbO4ssz7C5zZAZ2l51PZYjbU7uamkbLRFDNRyi6/qwKSpL53PiHNPpb6sn6A0vCisdfK+MSnULjLCkeNzwDmm4NS4Br/bGKi4DIqmHdn3QNF8LBclen9cQGbuSrN4Np0LJkxoiBTvXOQiBd1STm046VBeQ90bYypBkTra2cs+MI7e8VanfwZrpQC7YpSL4b/86U3+4A6gjbX9/swkrc1p+7g/Jmcs7bBPzw9djRknMGQII3qRep9z67CjkXUAqYZZHovzdSrzGEZd+zJlL82A3nm5eRw5ycrLzaPz6ZOGnpK535aDDuPul+pXpX6Br3k9AoE9jIrYrMhTcqAiBcPjCBDIy9WLLff4ryH2cNcvbRfAH3D/yxrkPIScGPXdhBKpOUo9IAw1464NXtv2CKHWbc0jsmXu6j3tSr1g+jgeLQ719mcWMg41kjyUHqrnjhitW99ZQtUgFeu9XU9pZMHsURURWQsXX1zsbaQsu1n/JsdjGf8vAAD//1C4UhI=" }