I have an elastic ingestion problem where the elastic agent successfully publishes documents, but they don't show up at all in Elasticsearch. What's more insulting is that the agent logs say that 9 events have been published to elasticsearch ...
. The Ingest Pipeline even has a failure processor that doesn't produce results either.
How do I inspect the documents that are being sent from the agent?
Original issue being investigated: No netflow data in elasticsearch for mikrotik router (fleet agent)