allow splitting out indexes by event.provider #450
Labels
elastic
Related to issue with external ElasticSearch/Kibana output
enhancement
New feature or request
logstash
Relating to Malcolm's use of Logstash
opensearch
Relating to Malcolm's use of OpenSearch
performance
Related to speed/performance
Milestone
As of release v24.01.0, the
MALCOLM_NETWORK_INDEX_PATTERN
andMALCOLM_NETWORK_INDEX_SUFFIX
environment variables allow splitting out Suricata and Zeek to a different index pattern from the one Arkime creates.It may be useful to add another replacer to the pattern definable in either one or the other of these variables (probably the suffix?) to further allow it to be split out based on the
event.provider
variable (suricata
vs.zeek
, etc.).The text was updated successfully, but these errors were encountered: