[Bro] smb_files.log, logstash, and kibana

erik clark philosnef at gmail.com
Tue Aug 7 05:41:54 PDT 2018


I have a field name collision on "path". Logstash is pushing into ES a
field of "path" with the file path on disk to the log being monitored.

In smb_files.log, path refers to the path on disk of the file being written
by smb. How would this best be resolved?
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://mailman.ICSI.Berkeley.EDU/pipermail/bro/attachments/20180807/052402cd/attachment.html 


More information about the Bro mailing list