# index in Elasticsearch must be lowercase, so we need to lowercase it
mutate {
@@ -23,7 +24,7 @@ filter {
output {
elasticsearch {
hosts => [ "elasticsearch:9200" ]
index => "kypo.%{[@metadata][eseventtype]}_evt.definition=%{[@metadata][definitionID]}.instance=%{[@metadata][instanceID]}.run=%{[@metadata][runID]}"
index => "kypo.%{[@metadata][eseventtype]}_evt.sandbox=%{[@metadata][sandboxId]}.definition=%{[@metadata][definitionId]}.instance=%{[@metadata][instanceId]}.run=%{[@metadata][runId]}"