Hi All,
I'd like to ship specific event logs from my Siem to ElasticSearch for further processing. However the output from the Siem is in the leef format and can not be changed.
Has anyone on the lists done this? If you have how did you setup logstash and the grok filter?
Thanks
TimW