Ask Your Question

chris_toph's profile - activity

2020-10-22 17:23:26 +0000 received badge  Famous Question (source)
2019-02-09 23:54:18 +0000 received badge  Notable Question (source)
2018-06-17 14:20:57 +0000 received badge  Popular Question (source)
2017-11-22 21:44:30 +0000 marked best answer Deduplication in tshark -T ek

Hi folks,

I'm trying to import a network dump, which I created via tshark -i en1 -T ek > packets.json to elasticsearch.

Using the bulk importer of ElasticSarch, the import fails, because there are duplicate names of the fields. I think, since version 6.0 elasticsearch is more strictly when it comes to checking for duplicates.

So, my question is, why there are some duplicate names for fields, like ip_ip_addr or ip_text. In my understanding they should have unique names, so that you can import those data into ElasticSearch.

Thank you for your help and BR Christoph

2017-11-22 21:44:30 +0000 received badge  Scholar (source)
2017-11-22 21:10:48 +0000 asked a question Deduplication in tshark -T ek

Deduplication in tshark -T ek Hi folks, I'm trying to import a network dump, which I created via tshark -i en1 -T ek &g