[Bro] Elasticsearch Writer vs logstash

Luis Miguel Silva luismiguelferreirasilva at gmail.com
Thu Jan 29 22:48:44 PST 2015


Dear all,

I'm interested in dumping my bro logs into an elastic search instance and,
based on what I was able to learn thus far, it seems I have two different
options:
- use the elasticsearch writer (which the documentation says should not be
used in production as it doesn't have any error checking)
- or use logstash to read info directly from the bro logs and externally
dump it into elasticsearch

It seems to me the logstash route is better, given that I should be able to
massage the data into more "user friendly" fields that can be easily
queried with elasticsearch.

So my question is, based on your experience, what is the best option? And,
if you do use logstash, can you share your logstash config?

Thanks in advance,
Luis
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://mailman.ICSI.Berkeley.EDU/pipermail/bro/attachments/20150129/64d5c7eb/attachment.html 


More information about the Bro mailing list