I was looking to use the Translate plugin https://www.elastic.co/guide/en/logstas ... slate.html but didn't see it listed in the NLS filesystem (probably because its a community maintained plugin). Maybe theres a different way to accomplish what I'm trying to do.
I have a firewall log that references a number of values (hundreds) in different scenarios. I'd like to be able to do a dictionary lookup on a YAML file formatted like this.
So if "1" replace with ICMP. Whats the best way to do something like that using the installed plugins? Would rather not need to write massive filters to grok replace.
After installing the translate plugin, I imagine you'll have no problem trying to parse out your YAML.
TwitsBlog Show me a man who lives alone and has a perpetually clean kitchen, and 8 times out of 9 I'll show you a man with detestable spiritual qualities.
Oh crud, my bad! I even typed it correctly in my terminal - not sure what I was thinking.
I'm glad you got this working, is there anything else I can help you with?
TwitsBlog Show me a man who lives alone and has a perpetually clean kitchen, and 8 times out of 9 I'll show you a man with detestable spiritual qualities.
jolson wrote:Oh crud, my bad! I even typed it correctly in my terminal - not sure what I was thinking.
I'm glad you got this working, is there anything else I can help you with?
At the moment I'm good on this issue. I have other questions that I'll eventually open another thread on as they differ so much from this topic. As always thanks for your help!
TwitsBlog Show me a man who lives alone and has a perpetually clean kitchen, and 8 times out of 9 I'll show you a man with detestable spiritual qualities.