Answer the question
In order to leave comments, you need to log in
How does logstash know what human-readable names to translate the CEF log into?
Hello.
I deployed the ELK stack, I send logs from the firewall to it via SYSLOG, in the CEF format.
input like this:
type => "syslog"
syslog_field => "syslog"
codec => "cef"
cs4Label=Destination Zone
cs4=Untrusted.
How can they be correlated to each other during parsing and sent to the database a pair of "Destination Zone = Untrusted"?
Answer the question
In order to leave comments, you need to log in
Didn't find what you were looking for?
Ask your questionAsk a Question
731 491 924 answers to any question