We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
1 parent f77ef28 commit c2aba9eCopy full SHA for c2aba9e
1 file changed
filters/linux/linux.yml
@@ -467,13 +467,4 @@ pipeline:
467
- cast:
468
fields: [statusCode]
469
to: int
470
- where: 'equals("log.type", "auditd") && exists("statusCode")'
471
-
472
- # Set default severity for auditd events (info level)
473
- # Auditd logs don't have syslog priority, so default to info
474
- - add:
475
- function: string
476
- params:
477
- key: severity
478
- value: "info"
479
- where: 'equals("log.type", "auditd") && !exists("severity")'
+ where: 'equals("log.type", "auditd") && exists("statusCode")'
0 commit comments