I recently did some experimentation with getting data from 'auditd' into logstash. Along the way it created lots and lots of unwanted entries in the elastic index.
EG: These are items like '#033.31;1mbuilds#033.0;m.keyword'
-> how long will these entries persist?
Similarly there are entries in the index that really really need more explanation. I'd like to put these all in a namespace (of sorts) so that my future self will have some clue where they came from.
EG. 'a0', 'ppid'.
In an ideal world I'd have these appear as 'auditd.a0', etc. I suppose I can 'mutate' them all but Im hoping there is a more direct route.