Good Morning
How is it possibile to "label" some filed? for example, actually filebeat put into the field "message" these information
"October 30th 2018, 14:23:46.839 30/10/2018 14:23:44 Added iexplorer.exe TCP 10.10.10.111:443 85.45.103.187:40948"
We would like Filebeat recognize these information:
Added ---> ACTION
iexplorer.exe ----> PROCESS
TCP ---> PROTOCOL
10.10.10.111:443 ---> IP1:PORT1
85.45.103.187:40948 ---> IP2:PORT2
thank you so much.
Stefano Bisi
