Hi,
I am ingesting the standards syslogs using the elastic agent "custom logs" integration. I am trying to parse the logs before indexing and for that I am using ingest pipeline. I have two processors for that: Grok and remove in a sequential manner. When I test the pipeline in ingest pipeline it works but when I use in the custom log integration in the section custom configurations: pipeline:example-ingest-pipeline and save and deploy the integration it throws error like this
@stephenb yes, I missed the space after pipeline. Error goes away but still pipeline is not integrated. I will update things how it goes. Thank you for the immediate response.
@stephenb Yes, it works. I just had to redo the integration and ingest pipeline. It wasn't working probably working because I was editing the the integration and pipeline. Thank you, now it works like a charm.
Hi @stephenb, now I could parse data and everything looks good. however, there is still one caveat - I can't run the KQL queries in Discover as it shows like this:
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.