https://github.com/elastic/beats/blob/master/x-pack/filebeat/module/zeek/connection/ingest/pipeline.yml#L118 `REG` should be `REJ` https://docs.zeek.org/en/current/scripts/base/protocols/conn/main.zeek.html
https://github.com/elastic/beats/blob/master/x-pack/filebeat/module/zeek/connection/ingest/pipeline.yml#L118
REGshould beREJhttps://docs.zeek.org/en/current/scripts/base/protocols/conn/main.zeek.html