I set up ELK and then beats on Zeek server to send data to Elasticsearch.
Everything is good except one: there are a lot of fields - 308
And it creates an element of inconvenience for me to create a search. I think I've done something wrong, set it up wrong somewhere. There are even fields with the prefix "suricata".
How did you send Zeek logs to the ELK? What is your configuration?
What inputs do you need from me?