Hello,
I would like to make services translation like this:
21/tcp => ftp
80/tcp => http
But the translation doesn't work.
So, my services.yaml file is like this :
"1/tcp": "tcpmux"
"1/udp": "tcpmux"
"5/tcp": "rje"
"5/udp": "rje"
"7/tcp": "echo"
"7/udp": "echo"
"9/tcp": "discard "
"9/udp": "discard"
"11/tcp": "systat"
"11/udp": "systat"
"13/tcp": "daytime
.....
And my Logstash Configuration
filter {
mutate {
add_field => {"application_name" => "%{[netflow][l4_dst_port]}/%{protocol_name}"}
convert => {"application_name" => "string"}
}
translate {
field => "application_name"
destination => "application_name"
dictionary_path => "/opt/logstash/conf/services.yaml"
}
}