I am trying to ingest juniper log via filebeat using juniper module
but it does not give me systemname and RT_FLOW anywhere in my ELK data. how do I get that?
source = dc-fw1
Can I modify this module and add my own process to retrieve/delete fields?
<14>1 2021-04-16T08:00:39.489-05:00 dc-fw1 RT_FLOW - APPTRACK_SESSION_CLOSE [junos@2636.1.1.1.2.140 reason=\"ICMP error\" source-address=\"10.10.94.62\" source-port=\"36931\" destination-address=\"10.25.63.18\" destination-port=\"161\" service-name=\"None\" application=\"SNMP\" nested-application=\"UNKNOWN\" nat-source-address=\"10.10.94.62\" nat-source-port=\"36931\" nat-destination-address=\"10.25.63.18\" nat-destination-port=\"161\" src-nat-rule-name=\"N/A\" dst-nat-rule-name=\"N/A\" protocol-id=\"17\" policy-name=\"20201029\" source-zone-name=\"trusted-ent\" destination-zone-name=\"trusted-prod\" session-id-32=\"62595271\" packets-from-client=\"2\" bytes-from-client=\"142\" packets-from-server=\"0\" bytes-from-server=\"0\" elapsed-time=\"3\" username=\"N/A\" roles=\"N/A\" encrypted=\"No\" profile-name=\"N/A\" rule-name=\"N/A\" routing-instance=\"default\" destination-interface-name=\"et-1/0/0.207\" uplink-incoming-interface-name=\"N/A\" uplink-tx-bytes=\"0\" uplink-rx-bytes=\"0\" category=\"Infrastructure\" sub-category=\"Monitoring\" apbr-policy-name=\"N/A\" amr-rule-name=\"N/A\"]"