I am new to using the Elastic stack. What is most important to me is to collect firewall logs from an ASA. One of the challenges is that I cannot not search for networks in the logs because the IP addresses are mapped to a text field.
I get an error when I try to install the template. I have to add the template in a separate post because I am exceeding the amount of characters allowed.
PUT _template/asa_firewall_template
{
"error": {
"root_cause": [
{
"type": "parse_exception",
"reason": "request body is required"
}
],
"type": "parse_exception",
"reason": "request body is required"
},
"status": 400
}
All I can say is that format is a killer and one must use a json validator with a good editor that can match brackets, I used VIM. And even if it is valid, it still may not be valid for Elastic. This was the case for me.
When I remove "default" I removed the wrong closing bracket.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.