04-12-2019 07:18 AM
Yeah, you'll need to create the file /usr/share/logstash/search-minemeld-src.json with the content mentioned in my previous reply.
My understanding of this was the "src_ip" would be checked against the "firstIP" and "lastIP" fields within the minemeld index. If the "src_ip" is lower than or equal to the "firstIP" AND if the "src_ip" is greater than or equal to the "lastIP", it would take its "sources" and "confidence" values (from the event in the minemeld index) and copy these to the event that its matched.
The dissect section essentially is splitting up the indicator into two separate fields (firstIP and lastIP).
With the above method, we don't need to know the CIDR address.
Hope this helps.
04-12-2019 11:36 PM - edited 04-12-2019 11:36 PM
Great @KevinAS . Thanks again.
I am documenting the Minemeld integration and use cases with elastic search . Thinking to take it with Community via either blog post or Github. You deserve a big credit for the Logstash configuration.
Let me know your interst and email ID. would like to connect with you and add you for credits for the github/documentation.
I am available @ firstname.lastname@example.org
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!
The Live Community thanks you for your participation!