I want to run a test, but I don’t want to use all my zeek cluster data. I do know how to output all my zeek logs in JSON output, but how can I output just a single log to JSON output (like the ftp.log)?
What I’m looking for: All the zeek logs output like normal (tab separated), PLUS the FTP log is output in JSON format as well. Can I break one out or is it all or nothing?