I have an index template called "suricata-ids" created by default from Filebeat. This index template has many fields that are simply not used by the suricata logs. How can i delete that unnecessary fields? Is it possible? It improves performance?
It's not worth deleting extra fields for older indices. You should look at customising the index template to remove the fields you don't want for future indices.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.