- Notifications
You must be signed in to change notification settings - Fork 25.8k
Open
Labels
:Data Management/Ingest NodeExecution or management of Ingest Pipelines including GeoIPExecution or management of Ingest Pipelines including GeoIPenhancement"" muted="" aria-describedby="MDU6TGFiZWwyMzE3NA==-tooltip :R1aqdb:">>enhancementTeam:Data ManagementMeta label for data/management teamMeta label for data/management teamhigh hanging fruit
Description
It is common for tools to output data in a combined format where one document may contain several entities.
For example, a tool that scans several hosts for compliance or vulnerabilities or an API that provides an update to every train/bus etc.
We really want to split all entities out to separate docs while copying some high-level information.
This is possible using Logstash and the Split filter but not possible with Ingest Pipelines.
The feature would allow this kind of document to be processed and split without having to include Logstash in the ingest chain.
ianmuscat, kapildawar, Alex3k, axelv, yasin-amadmia-mck and 85 more
Metadata
Metadata
Assignees
Labels
:Data Management/Ingest NodeExecution or management of Ingest Pipelines including GeoIPExecution or management of Ingest Pipelines including GeoIPenhancement"" muted="" aria-describedby="MDU6TGFiZWwyMzE3NA==-tooltip :R2hehb:">>enhancementTeam:Data ManagementMeta label for data/management teamMeta label for data/management teamhigh hanging fruit