Elastic 6.3 Field mapping of "IPORHOST"

Imho that are 2 different questions but anyway, I solved this question by splitting the "IPORHOST" pattern into e.g. (?:%{IP:src_ip}|%{HOSTNAME:src_hostname})

1 Like