We don't recommend making changes to the system data flows because of the risk of breaking downstream dependencies, upgrades etc.
(The filebeat and index templates are embedded in the docker image. The templates and mappings that are loaded into the cluster can of course be edited, but may be overwritten during cluster or ECE upgrades)
If something goes wrong then original_message is quite helpfull for debugging.
If all is OK then timestamp and original_message are removed.
I suppose we could PUT this pipeline and alter the index template using cron or some other mechanism.
It is not super clean but I prefer not parsing some documents than not parsing any at all.
I will keep you posted for additions to the other -logs- indices.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.