Hello everybody,
I'd like to ask how can I use database for geoip filter. I've created new config file for filtering logs, which worked pretty well I guess. Then I tried to redirect to another database GeoLiteCity.dat in /etc/logstash/ writing this in my filter database => "/etc/logstash/GeoLiteCity.dat and it showed me error in Logstash's file telling me that path is wrong or the file could not be read. I even tried the other database format .mmdb and it's not working for me either. Logstash is running on Docker image and /usr/share/logstash folders are missing. But it still works, I suppose Docker uses some symlinks or something (maybe this files /usr/share/GeoIP/*). My actual question would be, where should I put my .dat file to make it read that geoip database and is it possible to edit MaxMind's database somehow (.dat). Thanks for your help :)
--
Follow Security Onion on Twitter!
https://twitter.com/securityonion
---
You received this message because you are subscribed to the Google Groups "security-onion" group.
To unsubscribe from this group and stop receiving emails from it, send an email to security-onio...@googlegroups.com.
To post to this group, send email to securit...@googlegroups.com.
Visit this group at https://groups.google.com/group/security-onion.
For more options, visit https://groups.google.com/d/optout.