Hi ,
i want to bring zeek logs to Elasticsearch , but this two modules are not included
json.orig_bytes","json.resp_bytes
i have changed this file /usr/share/filebeat/module/zeek/connection/config/connection.yml
and delete this twi fields form drop fields , but nothing happed !
could ant one guide me what should i do to bring this two fields .
thanks .