Much obfuscation later:
{
"_index": "filebeat-7.0.1-2019.05.23",
"_type": "_doc",
"_id": "b4cq5moBJei9cPnCrClb",
"_version": 1,
"_score": null,
"_source": {
"agent": {
"hostname": "filebeat.example.com",
"id": "e39e30ea-0918-48fd-91f8-bc2eafec23f2",
"type": "filebeat",
"ephemeral_id": "1484f00e-abc1-40d4-98bb-62d5b136df69",
"version": "7.0.1"
},
"log": {
"file": {
"path": "/syslogs/f5.log"
},
"offset": 103867050
},
"f5": {
"server": "10.11.12.13",
"request": "/example-request",
"response_code": 200,
"agent": "Thing",
"verb": "GET",
"virtual_ip": "10.20.30.40",
"referrer": "https://web.example.com/",
"bytes": 30211,
"syslog_timestamp": "May 23 20:28:35",
"clientip": "1.2.3.4",
"appliance_hostname": "f5.example.com",
"virtual_pool_name": "",
"httpversion": "1.1",
"server_port": "80",
"virtual_name": "/Common/vip-80_sitea_virtual",
"response_ms": 119,
"timestamp": "23/May/2019:20:28:35 +0100"
},
"input": {
"type": "log"
},
"@timestamp": "2019-05-23T19:28:36.466Z",
"ecs": {
"version": "1.0.0"
},
"host": {
"hostname": "filebeat.example.com",
"os": {
"kernel": "3.10.0-957.12.1.el7.x86_64",
"codename": "Core",
"name": "CentOS Linux",
"family": "redhat",
"version": "7 (Core)",
"platform": "centos"
},
"containerized": true,
"name": "filebeat.example.com",
"id": "d7619efec8b24acf9ac7093f6f203d48",
"architecture": "x86_64"
},
"fields": {
"service": "f5-requestlogs"
}
},
"fields": {
"suricata.eve.timestamp": [
"2019-05-23T19:28:36.466Z"
],
"@timestamp": [
"2019-05-23T19:28:36.466Z"
]
},
"highlight": {
"fields.service": [
"@kibana-highlighted-field@f5-requestlogs@/kibana-highlighted-field@"
]
},
"sort": [
1558639716466
]
}