I have a question about the built-in bro grok patterns.
In Bro you can greatly change the fields that are present depending on what scripts/mods/policies you load.
When you look at their log-file docs MOST of the fields are optional. So can grok really do a comprehensive job labeling the fields?
Any help greatly appreciated 
More Info: Question about creating Brobeat