Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

ECS grok patterns for ingest node grok processor #66528

Closed
jakelandis opened this issue Dec 17, 2020 · 1 comment · Fixed by #76885
Closed

ECS grok patterns for ingest node grok processor #66528

jakelandis opened this issue Dec 17, 2020 · 1 comment · Fixed by #76885
Assignees
Labels
:Data Management/Ingest Node Execution or management of Ingest Pipelines including GeoIP >enhancement Team:Data Management Meta label for data/management team

Comments

@jakelandis
Copy link
Contributor

Elastic common schema (ECS) in an increasingly common way to represented indexed data.

Logstash has started the process for first class support via the grok filter and a ecs_compatiblity flag. The implementation is still a work in progress and the primary branch is here.

Elasticsearch ingest grok processor should also provide ECS compatible / better support for ECS data formats. For example: This diff illustrates the potential differences.

@jakelandis jakelandis added >enhancement :Data Management/Ingest Node Execution or management of Ingest Pipelines including GeoIP labels Dec 17, 2020
@elasticmachine elasticmachine added the Team:Data Management Meta label for data/management team label Dec 17, 2020
@elasticmachine
Copy link
Collaborator

Pinging @elastic/es-core-features (Team:Core/Features)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
:Data Management/Ingest Node Execution or management of Ingest Pipelines including GeoIP >enhancement Team:Data Management Meta label for data/management team
Projects
None yet
Development

Successfully merging a pull request may close this issue.

3 participants