Closed dougburks closed 4 years ago
Ingest node geoip includes continent_name and country_iso_code. These fields are not defined in our Elasticsearch template, so we should remove the extra fields from the ingest node parser config.
continent_name
country_iso_code
Looks good 👍 .
Published: https://blog.securityonion.net/2019/11/elastic-684-now-available-for-security.html
Ingest node geoip includes
continent_name
andcountry_iso_code
. These fields are not defined in our Elasticsearch template, so we should remove the extra fields from the ingest node parser config.