Do anyone have idea on how do we create a watchlist in ELK. In other terms lookup tables. This specifies a range of values say 50 or 100 or more in a single file. And save it as .csv or .txt
For Ex: there are around 50-100 source IP addresses and each cannot be mentioned in the condition in the query. So we put it in a file and call that file in the condition of the query.
How do we do this in creating a query in ELK, and that too in logstash.
Please throw some light if someone has come across such situation.