Hi,
I have an index template called "suricata-ids" created by default from Filebeat. This index template has many fields that are simply not used by the suricata logs. How can i delete that unnecessary fields? Is it possible? It improves performance?
Thanks you