[RFC] 0017 Remove log.original stage 2#1347
[RFC] 0017 Remove log.original stage 2#1347djptek merged 13 commits intoelastic:masterfrom djptek:rfc_0017_stage_2
Conversation
|
Thanks, @djptek, for continuing to advance this. I came across a use of |
|
@elastic/security-external-integrations This is a proposal to deprecate |
|
@ebeahan yep, there are a few more I would expect this could be resolved in Kibana through an alias, however that won't work in Beats and there may be further impact where I think that's less likely in Logstash, by the timelines but I'll look anyway & I will definitely need to do some digging in I will review this thoroughly update the RFC |
|
I ran Some of these were actually references to [Filebeat] [SIEM] Fileset for Cisco FTD logs #13286 where this change had already been implemented
The majority of references are mappings e.g. `"msg": {to:[{field: "log.original", setter: fld_set}]}`` Full list of remaining references was: |
|
Likewise Kibana has plenty of references to |
Co-authored-by: Eric Beahan <ebeahan@gmail.com>
Co-authored-by: Eric Beahan <ebeahan@gmail.com>
Co-authored-by: Eric Beahan <ebeahan@gmail.com>
make test? Ymakeand committed those changes? n/aProgress RFC 0017 Remove log.original to stage 2