[Bro] filebeat +elk
zeolla at gmail.com
Wed Mar 28 10:09:16 PDT 2018
Do you specifically need to send it to logstash or do you just need it to
get inserted into elasticsearch?
On Wed, Mar 28, 2018 at 1:07 PM erik clark <philosnef at gmail.com> wrote:
> I am trying to ingest bro 2.5 json logs into an elk stack, using filebeat
> to push the logs. Is that even the best way to do this? I have found MUCH
> outdated material on ingesting bro logs into an elk stack, but very little
> that is up to date, and some of which is up to date but is using older
> versions of software from elastic.co. If anyone has a modern bro/elk
> integration document they use(d) to set their environment up, it would be
> greatly appreciated if you could share. Thanks!
> Bro mailing list
> bro at bro-ids.org
-------------- next part --------------
An HTML attachment was scrubbed...
More information about the Bro