Ask Your Question

Revision history [back]

Here is project using the tshark + ELK. The project will build VM for you. https://github.com/H21lab/tsharkVM

You are right, the mappings json need to be first de-duplicated, here is the deduplicated output. Inside this project is also script which can help to pre-process the mapping json.

According to my tests, Elasticsearch and Kibana does not bear well to include all mappings fields for every wireshark supported field. So just select the fields which you would require.