I have been working with the ELK stack with great succes for a project! really thanks for the great stuff!
Recently, I would like to try have a go with using logstash to read a list of things to compare to, but I am stuck.
The situation is as follows:
- We have a list of ip addresses which we flag as dangerous.
- We have incoming log files which sometimes contain these ip addresses.
- We would like logstash to read this list and compare it with the incoming logs.
I know it is possible to make an if statement with a hardcoded array of the big list of ip addresses which is then compared with grokked log fields "src_ip" or "dst_ip", but this would mean i have to do a daily check whether the big array list has changed or not.
tl;dr: can logstash read an external file list, and let me reach this file list with a variable within the logstash configuration file?