Cribl 上传lookup 表,传入数据进event
cribl 插入lookup 表,来数据有针对性的插入字段,对event 的数据进行字段插入。灵活性强。
The Lookup
At long last, we're ready to configure the lookup. First, let's create the Lookup table we'd like to use.
Getting the goods
先下载一个lookup 表,然后上传到cribl : knowledge ->lookup.
For this next portion you will need a CSV file. Download the CSV of status codes here: HTTP Status Codes. The CSV will be downloaded to the default location configured for your browser.