Open investlab opened 5 years ago
Anyone bumping in to this, it is probably because you are running elk 7+ punisherVX has posted updated versions of the json files. For me his traffic template worked out of the box, and his threat template just needed a small adjustment (remove the "default" block that starts on line 8) Hope it helps, and I hope sm-biz and shadow-box keep these things going. They're really nice.
Thanks, I had to remove the "default" block from both files.
Work for me too without "default" block
Where can we find the updated files? Link?
Dear Shadow-box I'm using Elastic Stack v7.x. So I can't use "traffic_template_mapping-v1.1.json" and "threat_template_mapping-v1.1.json". Can you help me update this template for Elastic Stack v7.x? Thankyou!