diff --git a/packages/docker/changelog.yml b/packages/docker/changelog.yml index 35251ff580a..3a9edeeb695 100644 --- a/packages/docker/changelog.yml +++ b/packages/docker/changelog.yml @@ -3,7 +3,7 @@ changes: - description: Use ecs definition of the 'event.dataset' field for container_logs. type: enhancement - link: https://github.com/elastic/integrations/pull/11196 + link: https://github.com/elastic/integrations/pull/11672 - version: 2.11.0 changes: - description: Bump package-spec version to 3.2.2 to run on Serverless and stack version 9.0. diff --git a/packages/docker/data_stream/container_logs/agent/stream/stream.yml.hbs b/packages/docker/data_stream/container_logs/agent/stream/stream.yml.hbs index 6aaa32023d3..f36f19f36b7 100644 --- a/packages/docker/data_stream/container_logs/agent/stream/stream.yml.hbs +++ b/packages/docker/data_stream/container_logs/agent/stream/stream.yml.hbs @@ -3,6 +3,8 @@ paths: {{#each paths}} - {{this}} {{/each}} +data_stream: + dataset: {{data_stream.dataset}} {{#if condition}} condition: {{ condition }} {{/if}} @@ -16,5 +18,3 @@ parsers: processors: {{processors}} {{/if}} -data_stream: - dataset: {{data_stream.dataset}} diff --git a/packages/docker/data_stream/container_logs/manifest.yml b/packages/docker/data_stream/container_logs/manifest.yml index 6fdc811d27e..d53e55014b1 100644 --- a/packages/docker/data_stream/container_logs/manifest.yml +++ b/packages/docker/data_stream/container_logs/manifest.yml @@ -25,6 +25,14 @@ streams: multi: false required: false show_user: true + - name: data_stream.dataset + type: text + required: true + default: docker.container_logs + title: Dataset name + show_user: false + description: > + Set the name for your dataset. Changing the dataset will send the data to a different index. For more info look at [data_stream field](https://www.elastic.co/guide/en/ecs/master/ecs-data_stream.html). - name: additionalParsersConfig type: yaml title: Additional parsers configuration @@ -39,14 +47,6 @@ streams: # pattern: '^\[' # negate: true # match: after - - name: data_stream.dataset - type: text - title: 'Datasream Dataset name' - description: Name of Datastream dataset - multi: false - default: docker.container_logs - required: true - show_user: false - name: processors type: yaml title: Processors