I have certain fields which we use in Linux logs and can you please let me know what would be the Elastic common schema(ECS) name for those fields and how you define the ECS name for those fields ??
Most of the fields you mention here you'll find right away, either in the Base fields, or under the field sets event, process, host.
Some of the fields you mention aren't obvious in what they mean. So it depends on what's in there. If after looking at the docs, you're not sure where to map some of them, please ping me again here.
Final note, if ECS really doesn't cover a few of your fields, you're free to add them as custom fields. ECS is an inclusive schema. You map to ECS what you can, and you add your additional fields under a custom field set, e.g. myapp.algo
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.