CN Groot-Stream 配置模版

This commit is contained in:
gujinkai
2024-04-28 11:29:06 +08:00
parent 7c503f02da
commit 56278c5e25
2 changed files with 40 additions and 0 deletions

View File

@@ -174,6 +174,26 @@ processing_pipelines:
kb_name: none kb_name: none
#kb_name: cn_internal_ip #kb_name: cn_internal_ip
- function: EVAL
output_fields: [ sent_bytes ]
parameters:
value_expression: "sent_bytes == null ? 0 : sent_bytes"
- function: EVAL
output_fields: [ sent_pkts ]
parameters:
value_expression: "sent_pkts == null ? 0 : sent_pkts"
- function: EVAL
output_fields: [ received_bytes ]
parameters:
value_expression: "received_bytes == null ? 0 : received_bytes"
- function: EVAL
output_fields: [ received_pkts ]
parameters:
value_expression: "received_pkts == null ? 0 : received_pkts"
- function: EVAL - function: EVAL
output_fields: [ traffic_inbound_byte ] output_fields: [ traffic_inbound_byte ]
parameters: parameters:

View File

@@ -174,6 +174,26 @@ processing_pipelines:
kb_name: none kb_name: none
#kb_name: cn_internal_ip #kb_name: cn_internal_ip
- function: EVAL
output_fields: [ sent_bytes ]
parameters:
value_expression: "sent_bytes == null ? 0 : sent_bytes"
- function: EVAL
output_fields: [ sent_pkts ]
parameters:
value_expression: "sent_pkts == null ? 0 : sent_pkts"
- function: EVAL
output_fields: [ received_bytes ]
parameters:
value_expression: "received_bytes == null ? 0 : received_bytes"
- function: EVAL
output_fields: [ received_pkts ]
parameters:
value_expression: "received_pkts == null ? 0 : received_pkts"
- function: EVAL - function: EVAL
output_fields: [ traffic_inbound_byte ] output_fields: [ traffic_inbound_byte ]
parameters: parameters: