[Bro] [bro] elasticsearch template

Tim Desrochers tgdesrochers at gmail.com
Thu Mar 10 08:56:01 PST 2016


Anyone using elasticsearch create a custom template for all bro logs and all fields.  I’m using dynamic templates right now and it works fine but I’d like to have a bit more control over things and I’d rather not reinvent the wheel if its been done before.

My google-fu has returned minimal results and none are for all possible bro logs with all possible fields



-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://mailman.ICSI.Berkeley.EDU/pipermail/bro/attachments/20160310/f1f988d9/attachment.html 


More information about the Bro mailing list