Using script processor in elastic-agent integration

Need your help. I don't like that using kubernetes integration in elastic-agents we have one event_dataset for all logs: kubernetes.container_logs

I would like to split it into several. In filebeat this can be done with a script, but how to put this script into elastic-agent integration via kibana?

There is documentation, I have studied it, but something is not working. Maybe someone has encountered it and can advise?

I can at chime in and say that I've spent half a day trying to run the script processor in elastic-agent/Custom-log integration. What a mess.

Finally I was successful when defining the script on a single line in single quotes, instead of using the > yaml operator.

1 Like

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.