Skip to content

Add workaround to rename old variant of host field#10

Draft
widhalmt wants to merge 2 commits intomasterfrom
feature-ecs-1
Draft

Add workaround to rename old variant of host field#10
widhalmt wants to merge 2 commits intomasterfrom
feature-ecs-1

Conversation

@widhalmt
Copy link
Copy Markdown
Member

Fixes #1

@widhalmt widhalmt self-assigned this Feb 24, 2021
@widhalmt widhalmt marked this pull request as draft February 24, 2021 13:56
Comment thread filter-10-syslog.conf

if [host] =~ /^\w/ {
mutate {
rename => {
Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cant we just use the proper Name for the field in the grok filter?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Rework rules to work with ECS

2 participants