Hi, I want to try geoip functionnalities.
I import with ELK logs from many active directory controllers. I want to match IP from that logs with a personal file.
For example 10.12.x.x => research floor 1 or 10.15.x.x -> labs floor 6
I've found that I must use a filter in my logstash.conf
remove_field => [ "@version", "@timestamp" ]
source => "event_data.IpAddress" <--- the field containing the IP string
So where to put my source file and how to build it (csv or something else ????)
A great thanks for your help