We use custom UDP integration(fleet managed integration) to collect Linux auth logs. We set the default pipeline for auth logs which is [logs-system.auth-default].
We did parse the data as we expected. This data stream uses default logs* index template.
I would like to change it with the default index template.[logs-system.auth]
After changing this index template, rollover the index to see what happened.
But right now, there is no log in this index. stayed 255b, there is no document in this index. ı can not see logs in discover.
Actually, ı do not know what ı am gonna do. ı'm stuck.