I need help because I don't know how to select only the part of the message where it says "NMAP ping sweep Scan".
05/28-10:30:30:52.840974 [**] [1:10000004:1] "NMAP ping sweep Scan" [**] [Priority: 0] {TCP}
I got this:
processors:
- dissect:
tokenizer: ' "%{service.message}" '
filed: "message"
target_prefix: "message"
spinscale
(Alexander Reelsen)
May 31, 2021, 9:02am
2
This Beats Playground allows to play around with beats processors and extract the data, hope t hat helps to get started
https://andrewkroh.github.io/beats-playground/
1 Like
Ohhh, thank you very much
I have a question, what is the reason for this part of the code?
layouts:
- 2006-01-02T15:04:05.999999999Z07:00
spinscale
(Alexander Reelsen)
May 31, 2021, 11:17am
5
See Timestamp | Filebeat Reference [7.13] | Elastic - a list of timestamps that should be able to parse.. this one aims at nanosecond resolution and time zones I would guess
system
(system)
Closed
June 28, 2021, 11:18am
6
This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.