[ https://issues.apache.org/jira/browse/METRON-508?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16057739#comment-16057739 ]
ASF GitHub Bot commented on METRON-508: --------------------------------------- Github user JonZeolla commented on the issue: https://github.com/apache/metron/pull/586 @nickwallen So, I'm not entirely done with the documentation but I pushed it out for a quick, general review. In doing this, I noticed that some new default-on fields were added with the release of 2.5/2.5.1 (for example, `server_appdata` in [SSL](https://www.bro.org/sphinx/scripts/base/protocols/ssl/main.bro.html#type-SSL::Info) was added with 2.5). For now, I'm going to ignore those. > Expand Elasticsearch templates to support the standard bro logs > --------------------------------------------------------------- > > Key: METRON-508 > URL: https://issues.apache.org/jira/browse/METRON-508 > Project: Metron > Issue Type: Sub-task > Reporter: Jon Zeolla > Assignee: Jon Zeolla > Priority: Minor > Original Estimate: 2h > Remaining Estimate: 2h > > The current elasticsearch templates do not support any logs other than Conn, > HTTP, and DNS. We should provide additional templates so that an > out-of-the-box bro install can send all of its logs into Metron and they will > get probably indexed in elasticsearch. -- This message was sent by Atlassian JIRA (v6.4.14#64029)