Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[feature request] Usage with Elastic Common Schema (ECS) #295

Open
ebuildy opened this issue Aug 27, 2024 · 1 comment
Open

[feature request] Usage with Elastic Common Schema (ECS) #295

ebuildy opened this issue Aug 27, 2024 · 1 comment

Comments

@ebuildy
Copy link

ebuildy commented Aug 27, 2024

Elastic stack provides a specification https://www.elastic.co/guide/en/ecs/current/ecs-reference.html that defines a common set of fields to be used when storing event data in Elasticsearch.

The feature request is about create a formatter to support this schema, for example, the field file is an object https://www.elastic.co/guide/en/ecs/current/ecs-file.html that accepts sub fields path , name etc...

Supporting ECS make easier integration with file-beat and elastic stack .

@reidmorrison
Copy link
Owner

Great idea. Should be relatively straight forward to create a new formatter using this spec.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants