diff --git a/logstash/pipelines/zeek/12_zeek_mutate.conf b/logstash/pipelines/zeek/12_zeek_mutate.conf index 9ad57fcdd..4c15084ec 100644 --- a/logstash/pipelines/zeek/12_zeek_mutate.conf +++ b/logstash/pipelines/zeek/12_zeek_mutate.conf @@ -2485,7 +2485,7 @@ filter { mutate { id => "mutate_add_field_ecs_event_kind_alert" add_field => { "[event][kind]" => "alert" } } } else if ("_zeekdiagnostic" in [tags]) and ([zeek][stats]) { - mutate { id => "mutate_add_field_ecs_event_kind_event" + mutate { id => "mutate_add_field_ecs_event_kind_metric" add_field => { "[event][kind]" => "metric" } } } else { mutate { id => "mutate_add_field_ecs_event_kind_event"