as you known, Elasticsearch is unable to menage fields with a dot separator.
Until now I've used the Bro json output: the output logs were sent to
Elastich through Logstash; from Elasticsearch 2.0 this is not
Is there a way to substitute a dot with another character?
In logstash/elasticsearch there is a de_dot filter that works quite well. It has its bugs but it will get the work done.
Check the patch in my repo