[ 
https://issues.apache.org/jira/browse/METRON-508?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=15989024#comment-15989024
 ] 

Jon Zeolla commented on METRON-508:
-----------------------------------

We should also improve the tokenization to be more sane.  For instance, the 
addition of things like 
https://www.elastic.co/guide/en/elasticsearch/reference/current/analysis-pathhierarchy-tokenizer.html
 (forward or reverse, depending on the field) would be very helpful.

> Expand Elasticsearch templates to support the standard bro logs
> ---------------------------------------------------------------
>
>                 Key: METRON-508
>                 URL: https://issues.apache.org/jira/browse/METRON-508
>             Project: Metron
>          Issue Type: Sub-task
>            Reporter: Jon Zeolla
>            Assignee: Jon Zeolla
>            Priority: Minor
>   Original Estimate: 2h
>  Remaining Estimate: 2h
>
> The current elasticsearch templates do not support any logs other than Conn, 
> HTTP, and DNS.  We should provide additional templates so that an 
> out-of-the-box bro install can send all of its logs into Metron and they will 
> get probably indexed in elasticsearch.  



--
This message was sent by Atlassian JIRA
(v6.3.15#6346)

Reply via email to