[Oisf-users] padding eve.json with additional field

erik clark philosnef at gmail.com
Mon Oct 1 12:32:20 UTC 2018

I would like to pad eve.json output for alerts with an additional
field, in the following manner:


where is either the src or dest ip + its port, and is its complement.

This is trivial to do with logstash +elasticsearch, but I need to pull
these additional json values into Splunk, which doesn't have a rewrite
function to to this that I am aware of.

The goal is to have a Splunk clickable link like in Kibana. Please
advise! Thank you!!

