I am attempting to filter a winlogbeats stream in an ingest pipeline. One thing I want to do is strip out the whole agent tree as this is repeated in every record.
Is there a way to remove "agent.*" in one go?
Aside: it is also unclear to me if these field are "flattened" (i.e. do I need to use dot expander) and how would I know.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.