diff --git a/templates/beats/elasticsearch.openvpn.ingest.pipelines.yml b/templates/beats/elasticsearch.openvpn.ingest.pipelines.yml index 479ca04..17444ef 100644 --- a/templates/beats/elasticsearch.openvpn.ingest.pipelines.yml +++ b/templates/beats/elasticsearch.openvpn.ingest.pipelines.yml @@ -24,6 +24,11 @@ pipelines: field: "openvpn.date" formats: - EEE MMM d HH:mm:ss yyyy + - date: + target_field: "openvpn.date" + field: "openvpn.date" + formats: + - EEE MMM d HH:mm:ss yyyy - set: field: 'openvpn.event' value: 'client-connected' @@ -50,6 +55,11 @@ pipelines: field: "openvpn.date" formats: - EEE MMM d HH:mm:ss z yyyy + - date: + target_field: "openvpn.date" + field: "openvpn.date" + formats: + - EEE MMM d HH:mm:ss z yyyy - set: field: 'openvpn.event' value: 'client-disconnected'