-
Notifications
You must be signed in to change notification settings - Fork 4.9k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Support the ingest of the source address and the source port separately #34371
Comments
Pinging @elastic/security-external-integrations (Team:Security-External Integrations) |
I think these fields should be proposed to be part of ECS before Filebeat implements them. |
I didn't see that |
I think its usage predates ECS. I don't recall whether anyone proposed added it to ECS in the past. But since Beats are adding fields into the |
Pinging @elastic/sec-deployment-and-devices (Team:Security-Deployment and Devices) |
Pinging @elastic/security-service-integrations (Team:Security-Service Integrations) |
Hi! Looks like this ticket is still in our backlog. Trying to understand what to do with this request. Example of TCP log:
It doesn't look like we can change Would the addition of ip and port solve this issue?
What fields should we use instead if above is not acceptable? |
I think this is not doable. I had a branch to do it somewhen, but the ECS definitions precluded doing it. |
Understood. What is the appropriate resolution to this ticket? |
I think it can be closed, but please check with Andrew. |
@andrewkroh please cast your vote. |
Related
#9460
elastic/ecs#247
We have introduced
log.source.address
for TCP/UDP input which is contains both the IP and the port like 127.0.0.1:8080.However, neither the IP nor the port are collected separately, which means that it usually involves a dissect operation to get either the IP or the port separately for data analysis (e.g. aggregation of unique IPs).
Can we consider introducing separate fields for ip/port?
The text was updated successfully, but these errors were encountered: