New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Change the fields exported by flows #1291
Conversation
Export the following fields: "_source": { "@timestamp": "2016-04-03T21:27:20.006Z", "beat": { "hostname": "mar.local", "name": "mar.local" }, "dest": { "ip": "172.16.2.200", "port": 8081, "stats": { "net_bytes_total": 2768, "net_packets_total": 13 } }, "source": { "ip": "172.16.2.1", "port": 59720, "stats": { "net_bytes_total": 1394, "net_packets_total": 14 } }, "final": false, "flow_id": "EAT/////AP//////CP8AAAGsEAIBrBACyEjpkR8", "last_time": "2016-04-03T21:26:54.771Z", "start_time": "2016-04-03T21:26:54.771Z", "tags": [ "service-X", "web-tier" ], "transport": "tcp", "type": "flow" }, |
d74f7ba
to
c175da4
Compare
- name: ip4 | ||
description: > | ||
Innermost IPv4 source address as indicated by first packet seen for the | ||
current flow. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Can you use spaces instead of tabs? Just to keep the same formatting as in the rest of the file.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
It uses only spaces.
LGTM. @urso should check that nothing is lost in the reorg. |
|
||
|
||
==== mac_dest | ||
==== outter_vlan |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
oh, typo. Just figured it must say 'outer', not 'outter'. I'm afraid this error is all over the place.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
updated
c175da4
to
cc04290
Compare
|
||
for _, name := range ipFieldNames { | ||
source[name[1]] = getLocation(source, name[0]) | ||
dest[name[1]] = getLocation(dest, name[0]) |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
This sets "ip6_location" to "", even if no "ip6" address is in source/dest. We should only set field, if address really in event
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Thanks, I forgot to add the check.
9cd8615
to
e522f39
Compare
LGTM |
No description provided.