You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Note every field is also included in message.
The GCP integration in Elasticsearch parses message into a json.jsonPayload, extracts/converts the fields into ECS mapping. However it does drop this json field, so everything is only stored twice.
I've worked around it by dropping the jsonPayload field in an ingest pipeline, which helps on storage, but we're still paying for the extra data transfer and processing.
Ideally the document would only contain the json fields and no message, and then the integration would use the json fields instead. It might need some modification to the ingest pipeline to detect the presence of jsonPayload and ignore message.
The text was updated successfully, but these errors were encountered:
Related Template(s)
PubsubToElasticsearch
What feature(s) are you requesting?
PubsubToElasticsearch is duplicating every field in the message field, which leads to increased costs both in storage, indexing and transfer.
A vpcflow document that comes in can look like this:
When it gets through transformation and written to Elasticsearch, it is expanded and looks something like this:
Note every field is also included in message.
The GCP integration in Elasticsearch parses
message
into ajson.jsonPayload
, extracts/converts the fields into ECS mapping. However it does drop thisjson
field, so everything is only stored twice.I've worked around it by dropping the
jsonPayload
field in an ingest pipeline, which helps on storage, but we're still paying for the extra data transfer and processing.Ideally the document would only contain the json fields and no message, and then the integration would use the json fields instead. It might need some modification to the ingest pipeline to detect the presence of
jsonPayload
and ignoremessage
.The text was updated successfully, but these errors were encountered: