Skip to content

Commit

Permalink
Add events template to base package (#228)
Browse files Browse the repository at this point in the history
Endpoint will use the events-* prefix. To make sure things work out of the box also with events-*-* this adds mappings and settings for the events prefix to the base package.
  • Loading branch information
ruflin committed Mar 3, 2020
1 parent 20a7a39 commit 9035de6
Show file tree
Hide file tree
Showing 3 changed files with 173 additions and 0 deletions.
Original file line number Diff line number Diff line change
@@ -0,0 +1,15 @@
{
"policy": {
"phases": {
"hot": {
"min_age": "0ms",
"actions": {
"rollover": {
"max_size": "50gb",
"max_age": "30d"
}
}
}
}
}
}
Original file line number Diff line number Diff line change
@@ -0,0 +1,134 @@
{
"order": 1,
"index_patterns": [
"events-*-*"
],
"mappings": {
"_meta": {
},
"dynamic_templates": [
{
"strings_as_keyword": {
"mapping": {
"ignore_above": 1024,
"type": "keyword"
},
"match_mapping_type": "string"
}
}
],
"date_detection": false,
"properties": {
"agent": {
"properties": {
"hostname": {
"ignore_above": 1024,
"type": "keyword"
},
"name": {
"ignore_above": 1024,
"type": "keyword"
},
"id": {
"ignore_above": 1024,
"type": "keyword"
},
"ephemeral_id": {
"ignore_above": 1024,
"type": "keyword"
},
"type": {
"ignore_above": 1024,
"type": "keyword"
},
"version": {
"ignore_above": 1024,
"type": "keyword"
}
}
},
"ecs": {
"properties": {
"version": {
"ignore_above": 1024,
"type": "keyword"
}
}
},
"host": {
"properties": {
"hostname": {
"ignore_above": 1024,
"type": "keyword"
},
"os": {
"properties": {
"build": {
"ignore_above": 1024,
"type": "keyword"
},
"kernel": {
"ignore_above": 1024,
"type": "keyword"
},
"codename": {
"ignore_above": 1024,
"type": "keyword"
},
"name": {
"ignore_above": 1024,
"type": "keyword"
},
"family": {
"ignore_above": 1024,
"type": "keyword"
},
"version": {
"ignore_above": 1024,
"type": "keyword"
},
"platform": {
"ignore_above": 1024,
"type": "keyword"
},
"full": {
"ignore_above": 1024,
"type": "keyword"
}
}
},
"ip": {
"type": "ip"
},
"containerized": {
"type": "boolean"
},
"name": {
"ignore_above": 1024,
"type": "keyword"
},
"id": {
"ignore_above": 1024,
"type": "keyword"
},
"type": {
"ignore_above": 1024,
"type": "keyword"
},
"mac": {
"ignore_above": 1024,
"type": "keyword"
},
"architecture": {
"ignore_above": 1024,
"type": "keyword"
}
}
},
"message": {
"type": "text"
}
}
},
"aliases": {}
}
Original file line number Diff line number Diff line change
@@ -0,0 +1,24 @@
{
"order": 1,
"index_patterns": [
"events-*-*"
],
"settings": {
"index": {
"lifecycle": {
"name": "events-default",
"rollover_alias": "events-generic-default"
},
"codec": "best_compression",
"refresh_interval": "5s",
"number_of_shards": "1",
"query": {
"default_field": [
"message"
]
},
"number_of_routing_shards": "30"
}
},
"aliases": {}
}

0 comments on commit 9035de6

Please sign in to comment.