Hello all,
I have try to run stack ELK for fortinet's syslog.
It's works and on kibana I see the log, but almost all fields are not searchable and they have a before the name...
I have used on logstash kv filter and in this mode:
filter {
kv {
source => "message"
}
}
It's works fine because find all key and value but in kibana it is not searchable...
Hello @Badger, in Kibana settings, under Index management of elasticsearch I have select the index and select Refresh Index but the problem is the same...
It is necessary drop the current index? For me this solution it isn't a problem...
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.