Skip to content

Parse DNS Fields #83

@jonathan-buttner

Description

@jonathan-buttner

Create a pipeline that adds the following fields:

image

These fields are already populated by the elastic endgame endpoint.

Take a look at these docs for writing the ingest pipeline to do the parsing: https://www.elastic.co/guide/en/elasticsearch/reference/current/grok-processor.html

Related:
https://github.com/elastic/endpoint-dev/issues/7136

Metadata

Metadata

Assignees

No one assigned

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions