Hello,
We are looking at moving from 6.4.2 to 7.x amongst the changes would be moving from our current data model to the Elastic Common Schema (ECS).
I understand that the Elastic Ingest Nodes have these extractions 'built-in', but how can I move these regex's and extractions etc etc to a Log Stash Pipeline.
Is there a way for me to dump the ingest pipeline - so that I can move it to a logstash pipeline?
Thanks