Change GeoIP field name for dest_ip to not overlap with GeoIP for src_ip #184
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This commit renames the
geoipfield fordest_iptogeoip_destinlogstash.confand creates a new mapping inelasticsearch6-template.json.In logstash configuration, GeoIP is used for both
dest_ipandsrc_ipif both are present. However, the
targetfield have the same name(
geoip) for both, so in the end thedest_ipGeoIP will overwrite thesrc_ipone.Fixes #183