Create a pipeline that adds the following fields:

These fields are already populated by the elastic endgame endpoint.
Take a look at these docs for writing the ingest pipeline to do the parsing: https://www.elastic.co/guide/en/elasticsearch/reference/current/grok-processor.html
Related:
https://github.com/elastic/endpoint-dev/issues/7136
Create a pipeline that adds the following fields:
These fields are already populated by the elastic endgame endpoint.
Take a look at these docs for writing the ingest pipeline to do the parsing: https://www.elastic.co/guide/en/elasticsearch/reference/current/grok-processor.html
Related:
https://github.com/elastic/endpoint-dev/issues/7136