Hey Everyone,
I have had pretty decent luck with the Filebeat modules, I currently use multiple Cisco ingestions (ASA, FTD, Meraki), and I have the Umbrella information being recognized and parsed; however I really do not see any usable data. It is shows me the file name, path, aws url... but not a whole lot more.
I believe I am on version 5 of the Umbrella DB. Would love anyone comment at what I could start looking at. I am assuming this is working for some of you.
Kibana File look:
Another Kibana look: