I'm using logstash to process some data and I'm in trouble!! This is my situation:
- I'm reading alerts witg Filebeat from a file that has been written by a SIEM.
- I'm receiving these alerts with logstash and I want to check if "dstip" is a concrete one, and then add a field if matched.
Thanks in advance!!