_ingest processor

(Zachary Buckholz) #1

I am attempting to do what I think should be a simple ingest processor pipeline.

From filebeat I am doing the following

"description": "OpenAM Authentication Access Logging",
"processors": [{
"set" : {
"field": "type",
"value": "amAuthentication.access_pipeline"
"split": {
"field": "message",
"separator": "\t"
"set": {
"field": "openam.data",
"value": "{{message.1}}"
"on_failure": [
"set": {
"field": "error",
"value": "{{ _ingest.on_failure_message }}"

But my value in elasticsearch is

"openam": {
"data": ""

How can I access the individual array elements of the initial split?


(Mark Walkom) #2

What value is this?

(Zachary Buckholz) #3

I was hoping it would be the first element of the array returned from the split processor run on the message field.

(system) #4

