Hello.
I created an index pattern coming from snort in json format. I used logstash to create it
But now i would like to write rules (xpack is activated) in kql coming from my snort index pattern i created but it does not work. Please help.
I used this tutorial : Visualize Snort3 logs in Kibana using Logstash and Elasticsearch – AGHANIM BLOG