[ https://issues.apache.org/jira/browse/METRON-508?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16071475#comment-16071475 ]
ASF GitHub Bot commented on METRON-508: --------------------------------------- Github user JonZeolla commented on the issue: https://github.com/apache/metron/pull/586 I spotted a duplicate in taking a scan of the template, so I ran `grep '": {' metron-deployment/packaging/ambari/metron-mpack/src/main/resources/common-services/METRON/CURRENT/package/files/bro_index.template | sort | uniq -c | grep -v 1` to make sure that was the only one. I fixed it and pushed things up, along with other minor tweaks - Travis was successful so I plan to merge soon. I also put some thoughts for a follow-on PR in [METRON-1010](https://issues.apache.org/jira/browse/METRON-1010). > Expand Elasticsearch templates to support the standard bro logs > --------------------------------------------------------------- > > Key: METRON-508 > URL: https://issues.apache.org/jira/browse/METRON-508 > Project: Metron > Issue Type: Sub-task > Reporter: Jon Zeolla > Assignee: Jon Zeolla > Priority: Minor > Original Estimate: 2h > Remaining Estimate: 2h > > The current elasticsearch templates do not support any logs other than Conn, > HTTP, and DNS. We should provide additional templates so that an > out-of-the-box bro install can send all of its logs into Metron and they will > get probably indexed in elasticsearch. -- This message was sent by Atlassian JIRA (v6.4.14#64029)