diff --git a/packages/ti_anomali/elasticsearch/ingest_pipeline/latest_ioc.yml b/packages/ti_anomali/elasticsearch/ingest_pipeline/latest_ioc.yml new file mode 100644 index 00000000000..159db8ddb9e --- /dev/null +++ b/packages/ti_anomali/elasticsearch/ingest_pipeline/latest_ioc.yml @@ -0,0 +1,6 @@ +--- +description: Prepare documents before ingestion for latest IoC. +processors: + - set: + field: "labels.is_ioc_transform_source" + value: "false" diff --git a/packages/ti_anomali/elasticsearch/transform/latest_intelligence/transform.yml b/packages/ti_anomali/elasticsearch/transform/latest_intelligence/transform.yml index 9be15628f20..e50c67d7f1d 100644 --- a/packages/ti_anomali/elasticsearch/transform/latest_intelligence/transform.yml +++ b/packages/ti_anomali/elasticsearch/transform/latest_intelligence/transform.yml @@ -13,6 +13,7 @@ dest: aliases: - alias: "logs-ti_anomali_latest.intelligence" move_on_creation: true + pipeline: "1.23.0-latest_ioc" # Should be something like '{{ IngestPipeline "latest_ioc" }}' latest: unique_key: - event.dataset diff --git a/packages/ti_anomali/elasticsearch/transform/latest_ioc/transform.yml b/packages/ti_anomali/elasticsearch/transform/latest_ioc/transform.yml index eee5a3acaf3..943640e8bdd 100644 --- a/packages/ti_anomali/elasticsearch/transform/latest_ioc/transform.yml +++ b/packages/ti_anomali/elasticsearch/transform/latest_ioc/transform.yml @@ -13,6 +13,7 @@ dest: aliases: - alias: "logs-ti_anomali_latest.threatstream" move_on_creation: true + pipeline: "1.23.0-latest_ioc" # Should be something like '{{ IngestPipeline "latest_ioc" }}' latest: unique_key: - event.dataset