Skip to content

Commit

Permalink
Revert "Transform schema v2 (#270)" (#411) (#412)
Browse files Browse the repository at this point in the history
  • Loading branch information
pzl authored Aug 15, 2023
1 parent b33dd9d commit 139c87d
Show file tree
Hide file tree
Showing 10 changed files with 929 additions and 640 deletions.
Original file line number Diff line number Diff line change
@@ -0,0 +1,310 @@
{
"index_patterns": [
"metrics-endpoint.metadata_current_*"
],
"priority": 200,
"template": {
"mappings": {
"dynamic": "false",
"_meta": {},
"dynamic_templates": [
{
"strings_as_keyword": {
"match_mapping_type": "string",
"mapping": {
"ignore_above": 1024,
"type": "keyword"
}
}
}
],
"date_detection": false,
"properties": {
"@timestamp": {
"type": "date"
},
"updated_at": {
"type": "alias",
"path": "event.ingested"
},
"Endpoint": {
"properties": {
"configuration": {
"properties": {
"isolation": {
"type": "boolean",
"null_value": false
}
}
},
"policy": {
"properties": {
"applied": {
"properties": {
"id": {
"type": "keyword",
"ignore_above": 1024
},
"name": {
"type": "keyword",
"ignore_above": 1024
},
"status": {
"type": "keyword",
"ignore_above": 1024
}
}
}
}
},
"state": {
"properties": {
"isolation": {
"type": "boolean",
"null_value": false
}
}
},
"status": {
"type": "keyword",
"ignore_above": 1024
},
"capabilities": {
"type": "keyword",
"ignore_above": 128,
"doc_values": false
}
}
},
"agent": {
"properties": {
"id": {
"type": "keyword",
"ignore_above": 1024
},
"name": {
"type": "keyword",
"ignore_above": 1024
},
"type": {
"type": "keyword",
"ignore_above": 1024
},
"version": {
"type": "keyword",
"ignore_above": 1024
}
}
},
"data_stream": {
"properties": {
"dataset": {
"type": "constant_keyword",
"value": "endpoint.metadata"
},
"namespace": {
"type": "keyword"
},
"type": {
"type": "constant_keyword",
"value": "metrics"
}
}
},
"ecs": {
"properties": {
"version": {
"type": "keyword",
"ignore_above": 1024
}
}
},
"elastic": {
"properties": {
"agent": {
"properties": {
"id": {
"type": "keyword",
"ignore_above": 1024
}
}
}
}
},
"event": {
"properties": {
"action": {
"ignore_above": 1024,
"type": "keyword"
},
"category": {
"ignore_above": 1024,
"type": "keyword"
},
"code": {
"ignore_above": 1024,
"type": "keyword"
},
"created": {
"type": "date"
},
"dataset": {
"ignore_above": 1024,
"type": "keyword"
},
"hash": {
"ignore_above": 1024,
"type": "keyword"
},
"id": {
"ignore_above": 1024,
"type": "keyword"
},
"ingested": {
"type": "date"
},
"kind": {
"ignore_above": 1024,
"type": "keyword"
},
"module": {
"ignore_above": 1024,
"type": "keyword"
},
"outcome": {
"ignore_above": 1024,
"type": "keyword"
},
"provider": {
"ignore_above": 1024,
"type": "keyword"
},
"sequence": {
"type": "long"
},
"severity": {
"type": "long"
},
"type": {
"ignore_above": 1024,
"type": "keyword"
}
}
},
"host": {
"properties": {
"architecture": {
"ignore_above": 1024,
"type": "keyword"
},
"domain": {
"ignore_above": 1024,
"type": "keyword"
},
"hostname": {
"ignore_above": 1024,
"type": "keyword"
},
"id": {
"ignore_above": 1024,
"type": "keyword"
},
"ip": {
"type": "ip"
},
"mac": {
"ignore_above": 1024,
"type": "keyword"
},
"name": {
"ignore_above": 1024,
"type": "keyword"
},
"os": {
"properties": {
"Ext": {
"properties": {
"variant": {
"ignore_above": 1024,
"type": "keyword"
}
}
},
"family": {
"ignore_above": 1024,
"type": "keyword"
},
"full": {
"fields": {
"caseless": {
"ignore_above": 1024,
"normalizer": "lowercase",
"type": "keyword"
},
"text": {
"norms": false,
"type": "text"
}
},
"ignore_above": 1024,
"type": "keyword"
},
"kernel": {
"ignore_above": 1024,
"type": "keyword"
},
"name": {
"fields": {
"caseless": {
"ignore_above": 1024,
"normalizer": "lowercase",
"type": "keyword"
},
"text": {
"norms": false,
"type": "text"
}
},
"ignore_above": 1024,
"type": "keyword"
},
"platform": {
"ignore_above": 1024,
"type": "keyword"
},
"version": {
"ignore_above": 1024,
"type": "keyword"
}
}
},
"type": {
"ignore_above": 1024,
"type": "keyword"
},
"uptime": {
"type": "long"
}
}
}
}
},
"settings": {
"index": {
"codec": "best_compression",
"refresh_interval": "5s",
"number_of_shards": "1",
"number_of_routing_shards": "30",
"sort.field": [
"@timestamp",
"agent.id"
],
"sort.order": [
"desc",
"asc"
]
}
},
"aliases": {}
}
}
Loading

0 comments on commit 139c87d

Please sign in to comment.