# Enrich Fleet Integration

**URL:** <https://discuss.elastic.co/t/enrich-fleet-integration/355895>\
**Category:** Elasticsearch\
**Tags:** fleet\
**Created:** [March 21, 2024, 10:55am UTC](https://discuss.elastic.co/t/enrich-fleet-integration/355895 "2024-03-21T10:55:42Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Eran\_Hadad](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/eran_hadad/32/102407_2.png) [@Eran\_Hadad](https://discuss.elastic.co/u/Eran_Hadad)\
**Post date:** [March 21, 2024, 10:55am UTC](https://discuss.elastic.co/t/enrich-fleet-integration/355895/1 "2024-03-21T10:55:42Z")

</div>

Hi,  
I'm using Elastic Fleet to integrate with Azure Event Hub and import logs.  
One of the log fields is a URL.  
I want to create a new short URL filed that extracts the URL until the first question mark.  
**URL** : `www.website.com?user=1234`  
**URLShort** : `www.website.com`

I thought of achieving this by editing the integration and add a Processor, but I don't think it can be done this way.

I have tried editing the Ingest Pipeline but it didn't work.  
Any ideas how can I achieve this?

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [March 21, 2024, 1:56pm UTC](https://discuss.elastic.co/t/enrich-fleet-integration/355895/2 "2024-03-21T13:56:33Z")

</div>

> [@Eran\_Hadad](#):
>
> I have tried editing the Ingest Pipeline but it didn't work.  
> Any ideas how can I achieve this?

What have you tried and which ingest pipeline you used? This is exactly the way to do it.

You need to create a custom ingest pipeline named `logs-azure.eventhub@custom` and put your processors there.

---

<div class="post-metadata">

**Author:** ![Eran\_Hadad](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/eran_hadad/32/102407_2.png) [@Eran\_Hadad](https://discuss.elastic.co/u/Eran_Hadad)\
**Post date:** [March 26, 2024, 8:14am UTC](https://discuss.elastic.co/t/enrich-fleet-integration/355895/3 "2024-03-26T08:14:42Z")

</div>

Thanks for the response.  
I have tried editing the existing ingest - logs-azure.eventhub-1.9.2  
And added a step to create the new field.  
I didn't see any error but nothing happened so I'm not sure how to debug why nothing is happening.

---

<div class="post-metadata">

**Author:** ![Eran\_Hadad](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/eran_hadad/32/102407_2.png) [@Eran\_Hadad](https://discuss.elastic.co/u/Eran_Hadad)\
**Post date:** [March 26, 2024, 9:46am UTC](https://discuss.elastic.co/t/enrich-fleet-integration/355895/4 "2024-03-26T09:46:06Z")

</div>

I created the ingest pipeline `custom` as you suggested, as I see the managed pipeline is calling the custom at the last step.  
I added a script task with a simple script:  
`ctx.azure.eventhub.properties.requestUriShort = ctx.azure.eventhub.properties.requestUri.split('?')[0]`  
And added the new field to the data view.  
But I get an empty string and not the result I was hoping for, and I don't know how to debug why nothing is happening

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 23, 2024, 9:46am UTC](https://discuss.elastic.co/t/enrich-fleet-integration/355895/5 "2024-04-23T09:46:30Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
