What is the Logstash "host" field source data? #810
Replies: 1 comment
|
@barrydekong For a standard T-Pot/Logstash pipeline, So:
If you're looking for a unique identifier for the attacker or connection, the
One thing to note is that T-Pot 20.06.x predates the widespread adoption of ECS, so you'll often see fields like Could you clarify which
If this solves your problem, feel free to mark it as the accepted answer so others can find it easily. |
Uh oh!
There was an error while loading. Please reload this page.
There is "host" field at logstash for filtering the logs with hash value, can anyone tell me the host refer to what kind of host (host name hash/host IP hash or others. I think it should be unique identifier of the source network connection, please correct me if I was wrong.
All reactions