Logstash-patterns-core BRO_* not working?


(Blacktop) #1

I have a question about the built-in bro grok patterns.

In Bro you can greatly change the fields that are present depending on what scripts/mods/policies you load.

When you look at their log-file docs MOST of the fields are optional. So can grok really do a comprehensive job labeling the fields?

Any help greatly appreciated :slight_smile:

More Info: Question about creating Brobeat


Question about creating Brobeat
(Blacktop) #2

Here are the patterns I am talking about - https://github.com/logstash-plugins/logstash-patterns-core/blob/master/patterns/bro


(Blacktop) #3

More clarification: when I stood up a simple test with BRO_HTTP and my logs I saw that it was incorrectly parsing them.


(system) #4

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.