When using a filebeat module, some data manipulations seem to be done in two places:
- In an ingest pipeline
- in filebeat at input using filebeat/module/[modulename]/[module-sub]/config/...yml.
This seems to be opposite the idea of keeping the beat as light weight as possible.
And it seems to add complexity or confusion as to what data is adjust where.
My questions are:
- Why is the data manipulation split?
- Is this divergence a target direction or just sign of migrating to ingest with the goal for everything to be an ingest eventually?
- Is there any current easy and bulk way to replicate the local filbeat input transformations into ingest pipelines?
Appreciate any insight here.