I am looking for a solution for my ingest pipeline, in this case logs-system.syslog-1.6.4.
I added a KV-processor for customized syslog of my Raspberry Pies.
But with every update of elastic this add processor is gone and I have to add it once again.
Have you considered using an index template/component, that adds this processor to all indices of that form, so that you do not change or update the elastic internal index templates/indices manually?
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.