Well, the user agent is dissected by the User Agent processor, which has a target_field option - the default being "user-agent".
I'm not sure whether you can configure it to use the root event? Maybe by specifying an empty target_field?
I tried using rename processor and it creates large number of blocks. I am looking for some shorter way to move all those fields out of user_agent field.
In this case, you will have better luck posting your question in the Elasticsearch forum: https://discuss.elastic.co/c/elasticsearch They develop Ingest node, so they will be able to help you.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.