And when I looked at events published to ES, I see most of the docker metadata common or duplicate under "_source" as well as "docker" fields.
Is there a way to eliminate one of these sets. They seem redundant.
Hi Badre
Thanks for your reply. Here is most of my filebeat config file.
( Feel free to suggest other improvements if you see some. I am still new to filebeat )
Hi @john_eapen i am sorry but i meant to comment on another post. But i think the sitting you are looking for is drop_fields processor, with this setting your can drop other fields as-well except "type" and "@timestamp" since these are default fields to filebeat.
I hope this answers your question
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.