[Bro] Bro dot problem

Vito Logrillo vitologrillo at gmail.com
Wed Dec 23 13:15:31 PST 2015


Hi all,
as you known, Elasticsearch is unable to menage fields with a dot separator.
Until now I've used the Bro json output: the output logs were sent to
Elastich through Logstash; from Elasticsearch 2.0 this is not
possible.
Is there a way to substitute a dot with another character?
Thanks,
Vito


More information about the Bro mailing list