Skip to content

Instantly share code, notes, and snippets.

@RuMORDeN
RuMORDeN / gist:299c5245e680a72c44061b4891c535e2
Last active December 19, 2019 20:23
filebeat-7.5.0-cisco-ftd-asa-ftd-pipeline-query
#Setup Filebeat 7.5 per docs at https://www.elastic.co/guide/en/beats/filebeat/7.5/filebeat-getting-started.html
#filebeat modules enable cisco
#filebeat setup
#Behavior results from processing by filebeat-7.5.0-cisco-ftd-asa-ftd-pipeline pipeline. Bypass of this pipeline eliminates issue.
#Successful query of documents ingested outside of filebeat-7.5.0-cisco-ftd-asa-ftd-pipeline
GET syslog-000008/_search
{
"query": {
"match": {