* Add Pensando module init
* explicitly define the ECS version per testing
* updates to docs from make update
* updates for pensando module
* updates to documentation and db screenshot
* add dashboard export to repo
* update to add pensando beat
* Update filebeat/module/pensando/dfw/config/dfw.yml
Co-authored-by: Marc Guasch <marc-gr@users.noreply.github.com>
* Update pipeline.yml
Condensed all "remove" fields to 1 list of fields.
* Update pipeline.yml
Do not remove the payload_raw field.
* Update filebeat/module/pensando/_meta/docs.asciidoc
Co-authored-by: Andrew Kroh <andrew.kroh@elastic.co>
* Update config.yml
Added syslog_host and syslog_port values as suggested.
* Update docs.asciidoc
Added documentation for syslog_host and syslog_port as suggested.
* Update pipeline.yml
Removing payload_raw - this and json are, essentially, the same field and no longer needed after parsing.
* Update pipeline.yml
Changed checks if values are != null to use the filebeat specific ignore_empty_value: true instead.
* Remove set of event.module
Remove the set param for event.module. Filebeat should add this automatically.
* Apply suggestions from code review
Co-authored-by: Andrew Kroh <andrew.kroh@elastic.co>
* Update test.log
* Use convert instead of set for some fields
Changed ECS sets for IP addresses and ports to converts of type ip and
integer respectively.
* Updates for geoip and autonomous system
* add pensando dfw fields
* fixes from make -C filebeat update
* fixes for filebeat check
* make update changes
* Update filebeat/module/pensando/dfw/config/dfw.yml
Co-authored-by: Marc Guasch <marc-gr@users.noreply.github.com>
* Update filebeat/module/pensando/dfw/ingest/pipeline.yml
Co-authored-by: Marc Guasch <marc-gr@users.noreply.github.com>
* Update filebeat/module/pensando/dfw/ingest/pipeline.yml
Co-authored-by: Marc Guasch <marc-gr@users.noreply.github.com>
* Update filebeat/module/pensando/dfw/ingest/pipeline.yml
Co-authored-by: Marc Guasch <marc-gr@users.noreply.github.com>
* Update filebeat/module/pensando/dfw/ingest/pipeline.yml
Co-authored-by: Marc Guasch <marc-gr@users.noreply.github.com>
* remove old json file
* ran tests
* Update filebeat/module/pensando/dfw/ingest/pipeline.yml
Co-authored-by: Marc Guasch <marc-gr@users.noreply.github.com>
* gen after run of 'mage -v pythonIntegTest'
* Update fields.yml
* mage fmt update request
Co-authored-by: Marc Guasch <marc-gr@users.noreply.github.com>
Co-authored-by: Andrew Kroh <andrew.kroh@elastic.co>
(cherry picked from commit 4194408)