You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
At the point where logs are collected (by filebeat) and forwarded along (to logstash), we're already using adding tags at the source.
We'd like to add a custom setting (environment variable) for adding additional user-defined tags. This would allow for an easy way to do custom user-defined groupings and labels of traffic.
The text was updated successfully, but these errors were encountered:
And the tags being applied to zeek, suricata, and arkime logs:
I think the only thing I have left to do is some sanitizing of the inputs for the tags (figure out what characters can/can't be allowed) and it's done.
At the point where logs are collected (by filebeat) and forwarded along (to logstash), we're already using adding tags at the source.
We'd like to add a custom setting (environment variable) for adding additional user-defined tags. This would allow for an easy way to do custom user-defined groupings and labels of traffic.
The text was updated successfully, but these errors were encountered: