is it possible to have to " destination.geo.country_iso_code" field with the geoip plugin in logstash ?
I use it but similar output fields are "destination.geo.country_code2" and "destination.geo.country_code3" and these fields are not usable in the SIEM for destination country.
I was wondering if there is any way to do it (change output name, rename field or other), and want to understand the difference between filter and the processor which have this "coutry_iso_code" with the same Maxmind database (see GeoIP processor | Elasticsearch Reference [7.10] | Elastic)
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.