Skip to content
This repository has been archived by the owner on Apr 16, 2021. It is now read-only.

Data Fields

doug edited this page Aug 27, 2019 · 5 revisions

Please note! This wiki is no longer maintained. Our documentation has moved to https://securityonion.net/docs/. Please update your bookmarks. You can find the latest version of this page at: https://securityonion.net/docs/Data-Fields.

Introduction

This page references the various types of data fields utilized by Security Onion on the Elastic Stack.

The various fields types are described below.

Fields

Alert Data
Bro
Elastalert

Template files

Fields are mapped to their proper type using template files, found in /etc/logstash/. The current template files include:

logstash-template.json - mapping information for logs going into logstash-* indices
beats-template.json - mapping information for logs going into logstash-beats-* indices.

Clone this wiki locally