Ask Your Question

Deduplication in tshark -T ek [closed]

asked 2017-11-22 21:10:48 +0000

chris_toph gravatar image

Hi folks,

I'm trying to import a network dump, which I created via tshark -i en1 -T ek > packets.json to elasticsearch.

Using the bulk importer of ElasticSarch, the import fails, because there are duplicate names of the fields. I think, since version 6.0 elasticsearch is more strictly when it comes to checking for duplicates.

So, my question is, why there are some duplicate names for fields, like ip_ip_addr or ip_text. In my understanding they should have unique names, so that you can import those data into ElasticSearch.

Thank you for your help and BR Christoph

edit retag flag offensive reopen merge delete

Closed for the following reason the question is answered, right answer was accepted by chris_toph
close date 2017-11-22 21:44:46.057515

1 Answer

Sort by ยป oldest newest most voted

answered 2017-11-22 21:43:34 +0000

Uli gravatar image

There was a bug report for this issue.

It is fixed with current master version (2.5.X).

edit flag offensive delete link more

Question Tools

1 follower


Asked: 2017-11-22 21:10:48 +0000

Seen: 1,038 times

Last updated: Nov 22 '17