--
Follow Security Onion on Twitter!
https://twitter.com/securityonion
---
You received this message because you are subscribed to the Google Groups "security-onion" group.
To unsubscribe from this group and stop receiving emails from it, send an email to security-onion+unsubscribe@googlegroups.com.
To post to this group, send email to security-onion@googlegroups.com.
Visit this group at https://groups.google.com/group/security-onion.
For more options, visit https://groups.google.com/d/optout.
It turns out that I had a made a silly mistake -- my output configuration in /etc/logstash/custom didn't have .conf at the end of the file name and so it wasn't being pulled in properly. Once I updated that, and changed the mapping from "_doc" to "doc", the data started importing into the proper index.
Thanks again for the help.
To unsubscribe from this group and stop receiving emails from it, send an email to securit...@googlegroups.com.
To post to this group, send email to securit...@googlegroups.com.
Visit this group at https://groups.google.com/group/security-onion.
For more options, visit https://groups.google.com/d/optout.