I am looking for a solution for my ingest pipeline, in this case logs-system.syslog-1.6.4.
I added a KV-processor for customized syslog of my Raspberry Pies.
But with every update of elastic this add processor is gone and I have to add it once again.
Have you considered using an index template/component, that adds this processor to all indices of that form, so that you do not change or update the elastic internal index templates/indices manually?
This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.