diff --git a/docker-compose.yml b/docker-compose.yml index 6c111987..5f2d844e 100644 --- a/docker-compose.yml +++ b/docker-compose.yml @@ -35,7 +35,7 @@ services: environment: - LS_HEAP_SIZE=2048m elasticsearch: - image: elasticsearch:5.2.0 + image: elasticsearch:5.2.1 hostname: elasticsearch restart: always command: elasticsearch -E node.name="node-1" -E cluster.name="wazuh" -E network.host=0.0.0.0 diff --git a/kibana/Dockerfile b/kibana/Dockerfile index 5a11c0f2..da952588 100644 --- a/kibana/Dockerfile +++ b/kibana/Dockerfile @@ -1,4 +1,4 @@ -FROM kibana:5.2.0 +FROM kibana:5.2.1 RUN apt-get update && apt-get install -y curl diff --git a/kibana/config/wait-for-it.sh b/kibana/config/wait-for-it.sh index 2f675212..9aaea851 100644 --- a/kibana/config/wait-for-it.sh +++ b/kibana/config/wait-for-it.sh @@ -18,7 +18,7 @@ sleep 30 if /usr/share/kibana/bin/kibana-plugin list | grep wazuh; then echo "Wazuh APP already installed" else - /usr/share/kibana/bin/kibana-plugin install https://packages.wazuh.com/wazuhapp/wazuhapp-2.0_5.2.0.zip + /usr/share/kibana/bin/kibana-plugin install https://packages.wazuh.com/wazuhapp/wazuhapp-2.0_5.2.1.zip fi exec $cmd diff --git a/logstash/Dockerfile b/logstash/Dockerfile index 2eff489f..afb70d27 100644 --- a/logstash/Dockerfile +++ b/logstash/Dockerfile @@ -1,4 +1,4 @@ -FROM logstash:5.2.0 +FROM logstash:5.2.1 RUN apt-get update diff --git a/logstash/config/logstash.conf b/logstash/config/logstash.conf index 5ab0c42a..b9eafcfc 100644 --- a/logstash/config/logstash.conf +++ b/logstash/config/logstash.conf @@ -22,6 +22,10 @@ filter { source => "srcip" target => "GeoLocation" } + date { + match => ["timestamp", "ISO8601"] + target => "@timestamp" + } mutate { remove_field => [ "timestamp", "beat", "fields", "input_type", "tags", "count" ] }