Using something other than colons in field names?

2020-01-31 Thread Yerex, Tom
Good afternoon, Our Metron installation uses colons in the field names. For example, geo ip enriched data appears as “enrichments:geo:ip_dst_addr:country”. Under Kibana (and from what I read Banana), the colon cannot be properly escaped for use with Timelion. My question: has anyone

Profiler consumer stuck

2020-01-31 Thread Gonçalo Pedras
Hi, again I found a problem in my profiler consumer. For some reason my profiler won't consume new records from "indexing" topic. I checked the Kafka Consumer Groups and the current offset were 4 records behind, stucked. And whenever it consumes from "indexing" it says the data is old because