Ingest Node processor for Network Community ID #55685
Labels
:Data Management/Ingest Node
Execution or management of Ingest Pipelines including GeoIP
>enhancement
Team:Data Management
Meta label for data/management team
Describe the feature:
As a user that processes networking logs with Ingest Node, I would like to have an Ingest Node processor for populating the Elastic Common Schema (ECS)
network.community_id
field. At a high level this value is a hash of the source/destination addresses and protocol.This is a useful field for correlating all events related to the same network flow regardless of the flow direction. For example correlating Packetbeat events other network log sources.
References
network.community_id
fieldcommunity_id
processorThe text was updated successfully, but these errors were encountered: