How to get Host: field from tcpdump

(Wanderer) #1

New to Elasticsearch. How can we get the "host" field, as seen below in the sample from Wireshark, so we can view the data in Kibana?

Hypertext Transfer Protocol
GET /some/url
Connection: Keep-Alive\r\n
<Connection: Keep-Alive\r\n>
Accept-Encoding: gzip\r\n
<Accept-Encoding: gzip\r\n>
[HTTP request 1/1]
[Response in frame: 162]

(Steffen Siering) #2

I guess you're meaning the Host header field? Have you tried to enable send_all_headers in the HTTP plugin?

(Wanderer) #3

That was it! Thanks!

(system) #4

