Hi everyone,
I try to do logstash filtering, where i can get only couple lines from suricata's eve.json file. It have lot of information, but i want only like a " source ip, dest. ip etc" info to kibana. Any help ?
Thank you.
-Tony
Hi everyone,
I try to do logstash filtering, where i can get only couple lines from suricata's eve.json file. It have lot of information, but i want only like a " source ip, dest. ip etc" info to kibana. Any help ?
Thank you.
-Tony
More details please. What do your events currently look like? What would you like them to look like instead?
This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
© 2020. All Rights Reserved - Elasticsearch
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant logo are trademarks of the Apache Software Foundation in the United States and/or other countries.