diff --git a/conf.d/10-pf.conf b/conf.d/10-pf.conf index 3096982cf1eb8fe099b9f4e1958fa5cec27bd51e..0e39a3c2f2981d2afed3504e5e403640c22f8425 100644 --- a/conf.d/10-pf.conf +++ b/conf.d/10-pf.conf @@ -11,8 +11,7 @@ filter { locale => "en" } mutate { - copy => { "[message]" => "[event][original]"} - replace => [ "syslog_message", "%{message}" ] + rename => { "[message]" => "[event][original]"} } } }