I hope i'm in the right category. I am using pf sense + ElasticSearch 2.2.0, Logstash 2.2.1, Kibana 4.4.1New to the site and new to ELK. I am having an a couple issues and I am not sure if this is a problem or not, but when I do:
curl -XGET localhost:9200/logstash-*/_mapping/?pretty
I get the following, which is my mapping twice:
Again I don't know if it's an issue, or how to fix it. The other issue I am having is I don't get any geoip fields in my kibana discover area, but see it in the settings indicies. I don't know if they have to do with one another so I posted it here as well. Thanks for any insight to my issue.
Ok, I got further, but I am getting my information from pfsense and snort. It isn't breaking up the tcp string and that why I'm not getting separate IP's. Here is what it looks like: message:[119:2:1] (http_inspect) DOUBLE DECODING ATTACK [Classification: Not Suspicious Traffic] [Priority: 3] {TCP} 192.168.1.166:57811 -> 63.251.98.12:80@version:1 @timestamp:March 17th 2016, 13:22:52.000 type:syslog host:192.168.1.167 tags:PFSense evtid:33 prog:snort[79032] _id:AVOFmfae16oo5OzDbW9d _type:syslog _index:logstash-2016.03.17 _score:
What I can't figure out is how to separate the bold part. Any help? Thanks again!
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.