From 881ea89ac006510ce325152e6d7f72f70fb700e0 Mon Sep 17 00:00:00 2001 From: nin9s <strrrn@gmail.com> Date: Wed, 12 Jun 2019 17:46:39 +0200 Subject: [PATCH] fix for https://github.com/nin9s/elk-hole/issues/11 fix for https://github.com/nin9s/elk-hole/issues/11 --- ...tash-syslog-dns-index.template_ELK7.x.json | 115 +++++++++--------- 1 file changed, 58 insertions(+), 57 deletions(-) diff --git a/json/logstash-syslog-dns-index.template_ELK7.x.json b/json/logstash-syslog-dns-index.template_ELK7.x.json index e760e0e..18121d2 100644 --- a/json/logstash-syslog-dns-index.template_ELK7.x.json +++ b/json/logstash-syslog-dns-index.template_ELK7.x.json @@ -1,59 +1,60 @@ -{ - "index_patterns":[ - "logstash-syslog-dns*" - ], - "mappings":{ - "dynamic":"true", - "properties":{ - "source_host":{ - "type":"ip" - }, - "logrow":{ - "type":"integer" - }, - "request_from":{ - "type":"ip" - }, - "source_port":{ - "type":"integer" - }, - "ip_request":{ - "type":"ip" - }, - "ip_response":{ - "type":"ip" - }, - "dns_forward_to":{ - "type":"ip", - "fields":{ - "keyword":{ - "type":"keyword", - "ignore_above":256 - } - } - }, - "tags":{ - "type":"keyword", - "fields":{ - "keyword":{ - "type":"keyword", - "ignore_above":256 - } - } - }, - "pid":{ - "type":"integer" - }, - "pihole":{ - "type":"ip" - }, - "blocked_domain":{ - "type":"text" - }, - "date":{ - "type":"date", - "format":"MMM d HH:mm:ss||MMM dd HH:mm:ss" - } +PUT /_template/logstash-syslog-dns +{ + "index_patterns": [ + "logstash-syslog-dns*" + ], + "mappings": { + "dynamic": "true", + "properties": { + "source_host": { + "type": "ip" + }, + "logrow": { + "type": "integer" + }, + "request_from": { + "type": "ip" + }, + "source_port": { + "type": "integer" + }, + "ip_request": { + "type": "ip" + }, + "ip_response": { + "type": "ip" + }, + "dns_forward_to": { + "type": "ip", + "fields": { + "keyword": { + "type": "keyword", + "ignore_above": 256 + } + } + }, + "tags": { + "type": "keyword", + "fields": { + "keyword": { + "type": "keyword", + "ignore_above": 256 + } + } + }, + "pid": { + "type": "integer" + }, + "pihole": { + "type": "ip" + }, + "blocked_domain": { + "type": "text" + }, + "date": { + "type": "date", + "format": "MMM d HH:mm:ss||MMM dd HH:mm:ss" } - } + } + } } \ No newline at end of file -- GitLab