Sorry guys - I'm a newbie to ELK.
So I've got packetbeat working (sort of) fine on Win 10.
Local copy of Elasticsearch receiving direct docuemts from the beat. Kibana displaying everything - sort of.
Having edited the packetbeat.yml to include:
send_headers: ["User-Agent", "Cookie", "Set-Cookie"]
(note: I'm guessing that if "send_all_headers: true" is enabled then I don't need the line before specifying user-agent, cookoie and set-cookie)
I then restarted the packetbeat service expecting to see some http headers. Nothing. Do I need to modify the template file in-order to see additional content in what was being captured.
I checked the PS script to make sure I wasn't editing a YML file that wasn't referenced by the service (wrong path, name, etc.) but it all seems fine.
Any suggestions gratefully appreciated. I got this working fine on my mac but for some reason Windows is proving ticky.
I've not yet got onto the subject of "how do I now index the new fields that are being passed" (a subsequent question I'm afraid).