-
Notifications
You must be signed in to change notification settings - Fork 572
Out of the box ECS field mappings for Custom Input packages #4236
Copy link
Copy link
Closed
Labels
StalledTeam:Obs-InfraObsObservability Infrastructure Monitoring team [elastic/obs-infraobs-integrations]Observability Infrastructure Monitoring team [elastic/obs-infraobs-integrations]Team:Security-Deployment and DevicesDEPRECATED Deployment and Devices Security team [elastic/sec-deployment-and-devices]DEPRECATED Deployment and Devices Security team [elastic/sec-deployment-and-devices]Team:Security-Service IntegrationsSecurity Service Integrations team [elastic/security-service-integrations]Security Service Integrations team [elastic/security-service-integrations]Team:Security-Windows PlatformSecurity Windows Platform team [elastic/sec-windows-platform]Security Windows Platform team [elastic/sec-windows-platform]discuss
Metadata
Metadata
Assignees
Labels
StalledTeam:Obs-InfraObsObservability Infrastructure Monitoring team [elastic/obs-infraobs-integrations]Observability Infrastructure Monitoring team [elastic/obs-infraobs-integrations]Team:Security-Deployment and DevicesDEPRECATED Deployment and Devices Security team [elastic/sec-deployment-and-devices]DEPRECATED Deployment and Devices Security team [elastic/sec-deployment-and-devices]Team:Security-Service IntegrationsSecurity Service Integrations team [elastic/security-service-integrations]Security Service Integrations team [elastic/security-service-integrations]Team:Security-Windows PlatformSecurity Windows Platform team [elastic/sec-windows-platform]Security Windows Platform team [elastic/sec-windows-platform]discuss
Type
Fields
Give feedbackNo fields configured for issues without a type.
Currently the custom input packages (like TCP/UDP, httpjson etc) comes with the bare minimum of ECS mapping, very similar to how custom inputs worked in Filebeat, however this does not produce the best outcome for the end users, as functionality like
add_*_metadatafor example produces ECS fields, especiallyhostwhich is enabled by default.This issue is to discuss what the best practice would be for all Custom Input packages, and then used to track the status of applying any decided changes.
Packages: