Dynamic lookup processor #2186
Sometimes it might be only possible to collect additional meta-information for events on host collecting data only.
Proposal: lookup processor with running executable scripts
Syntax. Lookup forms a namespace for potentially different lookup backends like:
With lookup processor proposed here will be named
The exec lookup processor will execute some configurable query, which has to return an JSON-object. The JSON object will be treated like
The scripts stdout is read and parsed as JSON object to be merged with event
Conditions support are automatically provided to all processors by libbeat.
Example configuration filebeat:
Example configuration for metricbeat:
Proposed behavior to reduce the surface area of potential vulnerabilities:
(list partially inspired from here: https://httpd.apache.org/docs/2.4/suexec.html)