-
-
Notifications
You must be signed in to change notification settings - Fork 288
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Kape modules don't include hostname #357
Comments
could you confirm which version you're running? if it's a version before 20241217, please upgrade to that version, as the KAPE parsers have been entirely overhauled (and aligned to ECS field naming). If you're on that version, can you please provide sample records that are not parsing as expected? |
I am running 20241217 |
After I run the KAPE modules, I then scp the json files to /logstash/kape |
Thanks for confirming. Yes, .json files go into |
Ok, I did something. I removed all files in /logstash/kape, ran sof-elk-clear.py. I uploaded a new json file to /logstash/kape and nothing is showing when trying to view the kape-* dataview. |
It's possible that files with the same filename will not be loaded properly due to how filebeat tracks them. It's best to put them into subdirectories when running repeated loads (e.g. |
Should I be making sub directories named the computer names? Exp: |
the filebeat shipper will traverse through an arbitrarily deep directory structure. It's up to you how that looks. |
I'm not using filebeat agent. I am manually uploading the json output from KAPE to /logstash/kape. I ended up creating a new sofelk vm. |
SOF-ELK ships all locally-placed logs using filebeat |
Hi
When running the supported KAPE modules on a endpoint and outputs the supported SOF-ELK JSON, it does not include the hostname. Is there a way we can add this?
The text was updated successfully, but these errors were encountered: