Hi, I'm using windows integration to collect windows event logs, the integration settings offer a field to specify processor, but when try to use enrich processor I stop receiving new logs and i got the following error
Currently the processor field is for local beat processors. If u want to do anything with Elasticsearch pipelines, you'd have to modify the ones that come with each integration.
You have to be careful with that as every index template created by fleet managed integrations has a final pipeline already set to do certain fleet things.
Would it be sensible to add your processors to the pipeline .fleet_final_pipeline-1 ? That one appears to be used in all of the integrations via the template .fleet_component_template-1. I tested with an enrich processor on the pipeline and worked so far. Can't see yet why this would be a bad idea.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.