I'm sure this is already written somewhere, but I am obviously looking for the wrong words.
I just started using the SIEM in 7.2 and its working pretty good
I am using Filebeat modules for Zeek and Suricata. I want each of them to go into their own index something like filebeat-{MODULE-DATE} but I can't figure out how to do that. I'm assuming there is a module variable set somewhere..
Can this be done with filebeat? Or do i need to pass through a Logstash instance to accomplish this? Is there a list of filebeat system variables?
Yes all modules add data to the events and you can use them after to generate the index. If you define the index in the output using the following I believe you will get what you want.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.