-
Notifications
You must be signed in to change notification settings - Fork 25.8k
ECS grok patterns for ingest node grok processor #66528
Copy link
Copy link
Closed
Labels
:Distributed/Ingest NodeExecution or management of Ingest PipelinesExecution or management of Ingest Pipelines>enhancementTeam:Data Management (obsolete)DO NOT USE. This team no longer exists.DO NOT USE. This team no longer exists.
Description
Elastic common schema (ECS) in an increasingly common way to represented indexed data.
Logstash has started the process for first class support via the grok filter and a ecs_compatiblity flag. The implementation is still a work in progress and the primary branch is here.
Elasticsearch ingest grok processor should also provide ECS compatible / better support for ECS data formats. For example: This diff illustrates the potential differences.
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
:Distributed/Ingest NodeExecution or management of Ingest PipelinesExecution or management of Ingest Pipelines>enhancementTeam:Data Management (obsolete)DO NOT USE. This team no longer exists.DO NOT USE. This team no longer exists.
Type
Fields
Give feedbackNo fields configured for issues without a type.