{ASK} Filebeat 6.2 prospector (document_type)

(yurizal) #1

ELK 5.6.8
Filebeat 6.2.1
I have question,
For filebeat 6.2.1 on the prospector -> document_type is still used or not

- field:
      - SuricataIDPS
      - JSON
    document_type: suricataIDPS
  fields_under_root: true
  type: log
    - /var/log/suricata/*/eve.json*

(ruflin) #2

document_type was removed in 6.0.

You can still set document_type inside fields if you want. It seems above you use field instead of fields.

(system) #3

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.