-
Notifications
You must be signed in to change notification settings - Fork 285
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
GeoIP informations mapped for wrong IP #183
Comments
This is the part of the logstash config that you refer to right - https://github.com/StamusNetworks/SELKS/blob/master/staging/etc/logstash/conf.d/logstash.conf#L50 ? |
Yes - sorry, I'm not a logstash expert, but AFAIK lines 59-67 will override 50-58. I made a test renaming field at 62 (and re-creating the index in Kibana) and it seems to work properly, but I think that it should be the default :-) |
aha ok. Could you please do a pull request towards the git master for review? |
I will ASAP :-) |
The GeoIP information are extracted from the destination IP only (I think that this is caused by the logstash configuration, which logs the geoip result with the same key for source and destination IPs). In my opinion, these informations should be divided in
geoip_src
andgeoip_dest
.My setup is SELKS with a secondary NIC for passive interception (the NIC is linked to a SPAN/mirror port in the switch)
The text was updated successfully, but these errors were encountered: