I have this nut that I've been trying to crack for a while now.
I'm wondering if it is possible to edit a field or add a tag of the ES documents that match a watcher query. Ideally, when a log comes into my pipeline that is urgent I want to do two things:
1) Send an email to myself to alert that the error happened -- I can do this no problem
2) Put into the "tags" of the log that it has been "AlertedToMe". I'd either like to do this or change an existing field of the log to say something along those lines. I want to do this because I'd like to remove the errors that I've already seen, from my visualizations by simply querying: -tags:AlertedToMe and hiding all of the logs that I've seen rather than typing each log I don't want to see into the query box (I have hundreds of different ones to go through).
Is there a way to have watcher do this type of active tagging on documents in an index? Can I do it through "transforms"?