Logstash filter only couple lines from suricatas eve.json

(Tony Max) #1

Hi everyone,

I try to do logstash filtering, where i can get only couple lines from suricata's eve.json file. It have lot of information, but i want only like a " source ip, dest. ip etc" info to kibana. Any help ?

Thank you.


(Magnus B├Ąck) #2

More details please. What do your events currently look like? What would you like them to look like instead?

(system) #3

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.