the setup I'm working with consists of:
- machine A - where I'd like to install packetbeat
- machine B - where elastsearch is listening
I have DNS queries forwarded to machine A.
I would like to filter the DNS traffic coming to machine A based on a list of domains; in other words, for every query, if the domain requested is in the list I would like packetbeat to forward the DNS request to elasticsearch and ignore/drop every query that does not request any of the domains in the list.
Is this feasible?
Edit: I apologize for the vague question, I know that events can be excluded via processors "drop_event" and applying conditions. However since I have a pretty big list (1 million record) I wonder how that could be done.
Thanks in advance,