You'll need to convert the pcap time value into a time field that elasticsearch understands. Consider using logstash with the https://github.com/purbon/logstash-input-pcap plugin
You'll need to convert the pcap time value into a time field that elasticsearch understands. Consider using logstash with the https://github.com/purbon/logstash-input-pcap plugin
© 2020. All Rights Reserved - Elasticsearch
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant logo are trademarks of the Apache Software Foundation in the United States and/or other countries.