3 Sep
2019
3 Sep
'19
7:53 a.m.
On Mon, Sep 02, 2019 at 03:06:55PM +0000, Attila Szakacs (aszakacs) wrote:
We could give the user an option, to set multiple field mapping types when configuring the elasticsearch-http() destination, and if it is set, syslog-ng will try to create the index with the given mapping types before sending the logs. Although, it does not fit really well with the current implementation of elasticsearch-http(), it might be possible, that we can make it work.
ideally, syslog-ng should automatically generate the ES-mapping using type-hints and/or the json types as set in format-json.