You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
It is not easy to discover the index template for ECS from the documentation.
Motivation:
After going through the work of matching log fields to the ECS fields for a "custom" data sources, the next step is to load an index template into Elasticsearch. In order to avoid mapping conflicts in Kibana's index patterns, Elasticsearch searches, and unexpected errors in the curated Kibana UIs, the same mappings as other ECS content needs to be used.
Thanks @a03nikki for opening the issue and providing this feedback.
I wonder if moving some or all the ECS tooling usage and developer docs to also being on elastic.co could be help with these type of discovery issues, similar to what's done with Beats and Kibana.
Summary:
It is not easy to discover the index template for ECS from the documentation.
Motivation:
After going through the work of matching log fields to the ECS fields for a "custom" data sources, the next step is to load an index template into Elasticsearch. In order to avoid mapping conflicts in Kibana's index patterns, Elasticsearch searches, and unexpected errors in the curated Kibana UIs, the same mappings as other ECS content needs to be used.
Detailed Design:
Add a link from the documentation to the generated index template at https:/elastic/ecs/blob/master/generated/elasticsearch/7/template.json. The only reference to template is at Elastic Common Schema (ECS) Reference [1.6] » Using ECS » Conventions.
The text was updated successfully, but these errors were encountered: