Thanks Sebastian,
I do have logs being parsed from our Palo Alto and there are two different fields one for the PaloAlto System (data.source_address) and on for the PaloAlto GlobalProtect (data.public_ip) instead of data.srcip. Can I add two more 'stanzas' to the pipeline like this;
{
"geoip": {
"field": "data.srcip",
"target_field": "GeoLocation",
"properties": ["city_name", "country_name", "region_name", "location"],
"ignore_missing": true,
"ignore_failure": true
}
},
{
"geoip": {
"field": "data.source_address",
"target_field": "GeoLocation",
"properties": ["city_name", "country_name", "region_name", "location"],
"ignore_missing": true,
"ignore_failure": true
}
},
{
"geoip": {
"field": "data.public_ip,
"target_field": "GeoLocation",
"properties": ["city_name", "country_name", "region_name", "location"],
"ignore_missing": true,
"ignore_failure": true
}
},