From c3cb3653821a5256990f565dc12c00d2dcb2b9b8 Mon Sep 17 00:00:00 2001 From: James Rodewig <40268737+jrodewig@users.noreply.github.com> Date: Tue, 5 Oct 2021 17:08:16 -0400 Subject: [PATCH] [DOCS] Update ES ingest pipeline refs (#28239) ## What does this PR do? Changes several 'ingest node' references in the docs to 'ingest pipeline.' ## Why is it important? While a node with the `ingest` role is required to use Elasticsearch ingest pipelines, we no longer include 'ingest node' in the feature name. There are no official plans, but the Elasticsearch team has discussed removing the `ingest` role in the future. ## Related issues - https://github.com/elastic/elasticsearch/pull/70253 - https://github.com/elastic/elasticsearch/pull/78633 Co-authored-by: dedemorton --- auditbeat/auditbeat.reference.yml | 2 +- auditbeat/docs/fields.asciidoc | 2 +- auditbeat/module/auditd/_meta/fields.yml | 3 ++- auditbeat/module/auditd/fields.go | 2 +- docs/devguide/modules-dev-guide.asciidoc | 13 +++++------ .../config/filebeat.inputs.reference.yml.tmpl | 4 ++-- filebeat/beater/filebeat.go | 4 ++-- .../docs/filebeat-modules-options.asciidoc | 2 +- filebeat/docs/include/what-happens.asciidoc | 4 ++-- .../docs/inputs/input-common-options.asciidoc | 2 +- filebeat/docs/modules-overview.asciidoc | 2 +- filebeat/docs/modules/iptables.asciidoc | 4 ++-- filebeat/docs/modules/netflow.asciidoc | 2 +- filebeat/filebeat.reference.yml | 6 ++--- .../_meta/config/beat.reference.yml.tmpl | 4 ++-- .../monitors/monitor-common-options.asciidoc | 2 +- heartbeat/heartbeat.reference.yml | 6 ++--- journalbeat/journalbeat.reference.yml | 2 +- .../output-elasticsearch.reference.yml.tmpl | 2 +- .../monitoring/monitoring-metricbeat.asciidoc | 4 ++-- libbeat/docs/shared-config-ingest.asciidoc | 22 +++++++++---------- libbeat/docs/shared-geoip.asciidoc | 2 +- .../elasticsearch/docs/elasticsearch.asciidoc | 12 +++++----- metricbeat/metricbeat.reference.yml | 2 +- packetbeat/packetbeat.reference.yml | 2 +- winlogbeat/winlogbeat.reference.yml | 2 +- x-pack/auditbeat/auditbeat.reference.yml | 2 +- .../dockerlogbeat/docs/configuration.asciidoc | 2 +- x-pack/filebeat/filebeat.reference.yml | 6 ++--- .../module/iptables/_meta/docs.asciidoc | 4 ++-- .../module/netflow/_meta/docs.asciidoc | 2 +- x-pack/functionbeat/docs/overview.asciidoc | 4 ++-- .../functionbeat/functionbeat.reference.yml | 2 +- x-pack/heartbeat/heartbeat.reference.yml | 6 ++--- x-pack/metricbeat/metricbeat.reference.yml | 2 +- x-pack/osquerybeat/osquerybeat.reference.yml | 2 +- x-pack/packetbeat/packetbeat.reference.yml | 2 +- x-pack/winlogbeat/winlogbeat.reference.yml | 2 +- 38 files changed, 75 insertions(+), 75 deletions(-) diff --git a/auditbeat/auditbeat.reference.yml b/auditbeat/auditbeat.reference.yml index c69b933b110..f616e16c846 100644 --- a/auditbeat/auditbeat.reference.yml +++ b/auditbeat/auditbeat.reference.yml @@ -479,7 +479,7 @@ output.elasticsearch: # In case you modify this pattern you must update setup.template.name and setup.template.pattern accordingly. #index: "auditbeat-%{[agent.version]}-%{+yyyy.MM.dd}" - # Optional ingest node pipeline. By default no pipeline will be used. + # Optional ingest pipeline. By default no pipeline will be used. #pipeline: "" # Optional HTTP path diff --git a/auditbeat/docs/fields.asciidoc b/auditbeat/docs/fields.asciidoc index 94a6dfa0fc2..2b1ea54d853 100644 --- a/auditbeat/docs/fields.asciidoc +++ b/auditbeat/docs/fields.asciidoc @@ -2358,7 +2358,7 @@ alias to: error.message [float] === geoip -The geoip fields are defined as a convenience in case you decide to enrich the data using a geoip filter in Logstash or Ingest Node. +The geoip fields are defined as a convenience in case you decide to enrich the data using a geoip filter in Logstash or an Elasticsearch geoip ingest processor. diff --git a/auditbeat/module/auditd/_meta/fields.yml b/auditbeat/module/auditd/_meta/fields.yml index 92e004e3fc1..c12f26e4af4 100644 --- a/auditbeat/module/auditd/_meta/fields.yml +++ b/auditbeat/module/auditd/_meta/fields.yml @@ -858,7 +858,8 @@ type: group description: > The geoip fields are defined as a convenience in case you decide to - enrich the data using a geoip filter in Logstash or Ingest Node. + enrich the data using a geoip filter in Logstash or an Elasticsearch geoip + ingest processor. fields: - name: continent_name type: keyword diff --git a/auditbeat/module/auditd/fields.go b/auditbeat/module/auditd/fields.go index d78e256717a..922708a2a2f 100644 --- a/auditbeat/module/auditd/fields.go +++ b/auditbeat/module/auditd/fields.go @@ -32,5 +32,5 @@ func init() { // AssetAuditd returns asset data. // This is the base64 encoded zlib format compressed contents of module/auditd. func AssetAuditd() string { - return "eJzMXVuPHLdyftevIPwiG7DWznGQBz0cQMfOwyJOIsRSkCAIRlyyuofabrJFsmd2zq8Pipdu9m2ma6QcHD8I3tlh8Vb11VfFIvcNe4bLW8Z7qbx8xZhXvoG37F3+WYITVnVeGf2WfTiCA8YtMH8EVilopGM1aLDcg2RPl/B5lMVaI/sGHl6x9MW3r14x9oZp3sJb1juwrxhjzF86eMtqa/ou/Jy/i/+fv8x7JcMH+eu8UdylTzruj1HeQ+j4Yfhuq2rL48C97WEicqfEXbIqt1NapRpwF+eh3Sd4r1zHTyD3iaz3SQz7sXOQO0XGQRIEV3slF8tKEI//HlreTXoY9XCm+X9OHzL2WLFPFpxpTnBQ0n1iyjEHnnkT+mBKByMQRleq7mP3+Ilmn3KXnwZhZ9U0+FXPlWactbzrlK6ZqVBBoy2Egbog/ggs9Rw/HcR8Dw/1QzAT9ubPzBrjf3hIvyztadWi1hZ3xaom/a2t65pt3ZRNkFpa2U25hUoQuqD0ENWZILzeLztqMWXgBOGlHZKWn9DHwiJvdjTMBBql+5d9RvnhCOyPf/4dGzAlQXvlL2g7wQkJb+x1Ixh80NjVM1zOxo7znHTHhTC99sz1T63y6PAqYxnv0bi9EmFKsy6saYDSBQ7ptRsmVTTPEqVpudIUmR/yahSCoxRmbBDwMOujgRM0N7qAF952yBTcz/u7DYLnvQnuoTb28rVzynJwVsK0Hbe+Be3dQ8k7OmsEOLdKPSY9vI9fZNx7q556D+5hk5+I8y0/lbp9OBv7rHR9kMoCDv9yxVGtTFn01oL2LIlhg5jJHJ3prYDbU/wjfI/5I/fMW1XXYEEG44ETaL89X5zTq+29mg1bOXSRKBbbMe6cESrwxbPCn1mv1QtzRjyDn8xDgvNKj2Z1dTK/jV9mXEqLe/d3O7OBbe/jvy04x2s44HevjG40yYsTvGmu85gPmaln8UFmohJJApoS7zpuW2MPErQCmYjFiNdfetBiOqzG6Pp257kp0337BDYDd9ghxh0up6r1GFY8g9XQPLA/pl2y1N6FuMR5g1uNzVmvtP/lT5mQxeaMa8kE1witjTmBnU/HuRHFb6rAfEKhMXv8bRy7N4yzxtRKP7B3TRNn55iFJujJ+OtBUpYSqOGRn2Ks5XgL7MSbHqYDtuD6xu9Sil4EQDOWVVytKseHSDD7xg9eFBUEJDMdJCb7fZLzEwr5IWh1SaDalg+gtvTeG2QUIWyG/mWrLezPxodOc83Wo3YXFr8cQukYVDH0rdW8ogFZC5KgDUIyQY3swYxVtdK8mWkC/vf42wN79FEZtPFMHLmuo5EwVY3Tj5+HMIFr449gM115WEzVgTBa3jHZqOSp8c0JXjqFGHKZzGfQZZ6AM67WjwxeBHQ+MKozBkvDzI7c4f9I9sn1n+bcwTx9BuH36065XeVO+GMIu2wSyJ4Af+YCdb/vjM4gslOZCqC+U5Pelb/MK3wOOn4E9l0Y73c4+ojXSLh/TJ7mx4kgXMM3CVN+WOrCnWr/3XffTqsGWVnS0ZwpXHCxp/G3T+BQUlbNAKncsQ5sZWwL8oF9dD3qJ27+oAjwUm5cZJIt+oyALyggqga8gOgDgm9yjAWxcPuimt+VC/gbmixIxUIL1zFVaSNJkUdokFzpPOSAE0WShJNCr56svDK9lmg/P41yCvM9UKOwhbqgEGqctSqEHlqtitkTPd2UMkGQu2QscxlXBSCCMHPWYCPsPv42D2WJaoCKmlQheopKgWXfuw6E4k3ozzGjm8sPs47wX+r0n5WWaDNxFgNZibZqoQKLjFHO12iZ0ti7RsF6l4ukPLQUieejEsfQCgEoD1cYKxeDbYkGjd9nVcNrXGXGw+BXVpo8/2DXSjN+Em6KcZJ7vg/ikEjgt1llTVtwtRSJuBvJS1FkWnYNXIOvVOPBso6ji2RSuc44tZKxaZVekNE9cBfareMnFwuKcj3PlNNAOeFU7NMgU0rSKGPuuDUeZtFxplnKMWG0BuFRB3FfZj0K1R1pSB00xVRM2EvnTRLAHDSAvGpuOSRLlL2NBC0uUGK/M5GgvVXgSEMeQtHUOBO/UYM8f1oYEsIPpRsH9oTdWCYaheGu0nmVBvCad+HUX2mQCBeGbQKlviHcdbTldzjmlNNagiC34kjVTWiq0E55EL63CbkWgmtBFTzuKLd1HxKCMUgKFO4Es2TJAAP8830wgO3WYaDXigQDMYEuy3ZDfFHoIBEAQ9M1RPFgWwxCSQuc2kRTL7HE9lqjhXbW1Ja36INm/dWWa28syTw73qZjZcd411lzwj5Ghj8nriE9SvQVQ6MCurbsxnRUdZxzkyEciXCsXE65zHfHk/Lj3l9Yn1SSti1Tc9irqCFZmExNaQZVhVH0EMjHnJ4RIX89n1pBG/bl/j/8N/PwMreJireqIS1SwQqs8UaYJQiQ4CYpy7+++5XxpjZW+WO75e66iqb4YMOKVsaeuZUYbFsQF9aCP5qFK/XQkqRPcTLksiMJdZO8xxyNf/6qAIX/w9c1/9PXNf/lq5ofjfNU9ozrmNtRyVfTGUtyHo0RCMvgz8Y+s6L1EM5RJSb2iM3W/Ru8kP1bgA1sx8QY3QwGTQLXZHzIeiql62DUaqGzDZU3T9cxUecFe7prc7ZXUvCOP6lG0TAfA5qXsa1a8GHNbf0VuDDlTynZyFa4k4bzG9DIM0ikUsM5YHtK20cBzIFHo5ibL37n8MTFc2PqQ6NamurFLiLBeu1YksO+9NADK4h2QSToFMLYyxrPErw70JIbmWhHr6pOUCgIGyuYykQBzX+D6G2QhS0TMQkpdwwdTmqBHRrOh45knbi3eRodksZQPnF1GqaR92hRZyFEJ3s1yayUQl3tIJ4QvHbxsGYjWWYamsxGxsO9mZgnrjXQKHJqEvfP6IiCIFnH6wXAAsdQixZUhkPU1DKpSoy+5yzk1L4R/oUKNye0R2E0EjzmvF3ZMGKsOuzXZrzqAFWStMq55iTocjhbcYXdLORPTmlJHbz7z1+ZBKHCkXAImUD+FE/iV1DXDqtFztSbilld54MvKdH6rWkZZ6c5GUHL1ECaTrbKwI1T/qk8I1/04VQNpwN+wZCgTNUhHF3zqoom6sqBiGnkAXRlrFC0BUc7xyWIjQG9KXOe+37uqnGJT6Lr71nj0WP/+v4jE8YuiIBFe6WIHsrSWKpLKwQUlQg0Onm1zmBaZjD3/lISqcWwJOiI4tGDBL8WmFWclMBPLCjr9CQIHSyz0c9viKjVKRmH6xuln3Pa2oGWC210/dNnEvt0XRcaRVi8Crb8f35+88v/UkF8zhRXM2xieky/K/vjjygxtsTQ1F1cNVfu6KLoTu21YyewAWfXjV6YlqQaZlzheITcKL2aeUPkJuJpiaMJsq+haXZTJ5LVD6W1IQ0wyiiPoobdbLij2n8sPwwtrw8/VHOS1ke5Q2x08Nw9T6ukBktXFInh7GsYpdJHsOomh50yIyJUpcYRruYc35H8TixRvDSGywnipjTPPNr55qkB1HAH1JN+xOqsg0Xb0Z+feKPkIQHYPZo9bTrMn5j3S9MvbHI+0u6FauCP7/9ryDqssxli2KI6MSLSetDSchESoRSx4I+Inj57qFBD+vhbPLmdI+gdfirVY111UoroWx/fh5xzbXnLKsvrQMPGGoUV3aUlawNUxOTChE+vQduppTKDECFtxjIhu0ACtixqJ6QhM6WGzJ2FkzK9izeU1gJd42jscdDkseZ2ju70yo78ydYBniKWi0xMbqNgBLVLKvdMCtuUe76pWB23Y8p+t5Mog57sKaKktfqRBkgnaw3oeiivH3a+ajgthupAD7njtVPinqidnH38uLQjYrWNA4GEI1carqSzQxRQW2LaLNL/qDxbueIDLVMedH1nEg7Vs6WVNKHX5m0oyzAVa6E19oL88V/+Mo9bQtrlHrc9Zl2SGUgQSoZ816yPu6J0nMGuKB1XRxw5tTIO5WMzLjzYnITZweIRer9Vhgc5y+lajqf3qiKZZe+Z0h5sxcVG2kS0JLvMYdO04HYm82gMCTvHM19sGY/hEnURuEgrZ2+4y+SaTtxj2+vJVbpB8an+M6R1rqWbnSJpxbUs2fRk5cyVP3hFO+jcOF1BWayQNXiqkKEmRQapyVowjUZCRKycONuFWlTMig8lZMQtQWslU2waSWRvppFUBodQdsd+Sg5t8GzlvfYYWONsSqkDBzO2pcXtsavG1K/dtHV59ESkYWiKmX3NYHYm3N8RSobbI9zW4MNFnjLrcyVkaTkpFLpdXHbmnlZ0N63lje030gGh8zu9zkwWkf8k3rOU82QMDY6TA8wMAtsDn7MFJdquvGS5TwEw4jVVaJwLmFeUtjGC6KjOMVIKZe3pvK0QMoGM0WntdYKxLMSaVjnRI04UNHysWyatMY/3C0PdOXKNnOC7ymkUlQ+XdRihKmHmPyZn1CQoLc+od0KphIr3jX9zB26kpoForqehQixGBbsB6FLwFoQgMp31amYDnXzHnTuTITUqZ2VsOGoPMoyViN31Eu/CbhArVs/UwodcanfPdmTOn1G7VNrppeBJ4HWi8ZYyM1QW6lw/eSgibxq0LzaBuCTR2LbzmkVpyL6DlnRLB9v1vFF/3XVLJ6S0aAdF9EoT8pFoJo3DUx3rR6KWmElOmHmVpoSTfup4y2T62ljN0+evwZrJRdyR2ROzyYVjWqvHxY36imTZJOZdeKIY+FRcNcSamFm4kySsHZIpTYuplb4VUp9Ifj/ZHWu5OG6cRZYJtV0y25Z3V9NxIe9FPFUfjr2THmyWYXx1Zv66TmAPxMz0kOt2COsrqW4HX4g1LdN3MuYb9jdxQV+eLp62DmPy27EvPR9eCigFjUtCPRqcF6SEtEhxz27ipOnOc/D+O5kHIjK1XAcB+XapDmogOflkGrmZfArxAsmblimGnR5VUsus0xHq4/sNphFcNPGO98JDLx/TUkb4hpiWjI+kfOnB+aHQJb/OF+Rt1Ls44qlyLBLfJl/5XR6Sq0pt0oUcpWOOZUlu/wY2g6p0aDnNm88zadh+/gRDTmas3VkhgnnMuW6eMQZ0oVeR7D1pffp8ICaKU3Z4k5BZ4I52G65IYTEJ2oRcH0+CQvS3efuuUY6cSZtzqZiqR0nblZjUzErGhT3Zlaeedn04pZlc/5RZRu/C8UpJ7Ruja8cGZjxBZpLdlchM8FRUIJ2EDksQ/X/KPvWWZFkf/+ORdUbpoKCh7HA9LxRp/h0XC0rVdK9dulbwk1Qu3KjdLOO9L8MyVdKdWZZIV6lcau4nV0qtOprEJp/SOqN5cY1pQOE78+w7i1Y9uRhxTOCnciMUoKr1Nz2JhLs8PblVY6qB9PJRVI4YyDgIrwhM73QMQ6Zd6w4veiuR5K+9QLR1IVq19d23PkKkrlpew40LII2859Q9q/ni5P3WmfuBuHr5kc7Bv1w/dEiF7pQezsdQdhdtIoXeZ+6yqKoPDzdqs55Rvp9T3Eoop2Ca5AyGCEhCA36j3DVW2c/kTuvHN9/1K2tZt4a0QvGLYtaVF/Qm8Q1BquXn+ZUB520fnrxYdnN3L5OHXpZyZ1fltyUPj0f2Wr1c6zHNKQpm3+PXf2SqO/1j+PeffswZnbUX6MYnVwmTJD+9Wpy9pkeGXpUdlk/2rj/GGx/yjU+v5QcbX62MbXyO7p1mxsoQkzTpTTefdCCPgVkQoIYEVPFOKQY1g6QzWIg3+rxBcIw6Ex+uk0aEGDS9vBjfjFduwDtVhcdOrC1CxfwSQ2aP+RWN8CaTsdjmk9Ki6SUcLD8f0nDzW/eDnMlb99OHSc/caqXrO1cZR/swPUzdWGTUvtzX8k9R/AW4z48FpZHGtSteVZy96Tj+jYtE7YKwfFzHtQy/G67HSjhBY7qQBcBfSnjqx2Kcrredcemhs8kTwDWYdPY5R7PVieI0Q5P8VzfCAKFSOr92K4w+gVYhU6g0E9wBu5g+1caN4QZoq8Rx3O7exZAuSw8Rl9Lsd1M7z90R9eFR1+A8+zcjYfl2clk0ifQbtD9o4tsI0zccx4K1tGdR6uLhcOUv37Yn5S/zTizUyuhv2k0UuZiN6bW3l4Ny5kCtPi17+zXKYY9//HsoQ1087m4mrHbQPzCHED/tmw/GsMr3EoLSN9yHHx5e/V8AAAD//+Sz5kQ=" + return "eJzMXUuPHDlyvvevIOaiGUBdM94xfNBhAe1oDw2PYcEjGTYMo8RiRmZRnUmmSGZV1/56I/jIZL6qMqrlxc5BmK4uBl8RX3wRDLIf2TNc3jHeFdIVD4w56Wp4x96nnwuwwsjWSa3esU9HsMC4AeaOwEoJdWFZBQoMd1Cww8V/HmSxRhddDbsHFr/47uGBsUemeAPvWGfBPDDGmLu08I5VRnet/zl9F/8/fZl3svAfpK/zWnIbP2m5OwZ5O9/xrv9uIyvDw8Cd6WAkcqPETbJKu1FaKWuwF+ug2SZ4q1zLT1BsE1ltk+j3Y+MgN4oMgyQILrdKzpaVIB7/3Te8HfUw6OFE8/8cP2TsqWRfDFhdn2AvC/uFScssOOa074NJ5Y1AaFXKqgvd4yeKfUldfumFnWVd41cdl4px1vC2lapiukQFDbbgB2q9+COw2HP4tBfzI+yqnTcT9vhnZrR2P+3iL3N7WrSopcVdsKpRf0vrumRbN2UTpOZWdlNuphKELig9BHUmCK+2yw5aTBk4QXhuh6TlJ/Qxs8ibHfUzgVqq7mWbUX46Avvjr79jAyYLUE66C9qOd0LCaXPdCHofNHT1DJezNsM8R91xIXSnHLPdoZEOHV6pDeMdGreTwk9p0oXRNVC6wCG9sf2ksuZJYqEbLhVF5qe0GpngIIVp4wXsJn3UcIL6RhfwwpsWmYL9ZXu3XvC0N8EdVNpcXjunJAdnJXTTcuMaUM7uct7RGi3A2kXqMerhY/gi484Zeegc2N0qPxHnW34qdrs7a/MsVbUvpAEc/uWKo1qYsuiMAeVYFMN6MaM5Wt0ZAben+If/HnNH7pgzsqrAQOGNB06g3Pp8cU4P63s1Gba06CJRLLZj3FotpOeLZ4k/s07JF2a1eAY3mkcB1kk1mNXVyXwYvsx4URjcu3/YmfVsexv/bcBaXsEev3tldINJXqzgdX2dx3xKTD2J9zIjlYgS0JR423LTaLMvQEkoIrEY8PpbB0qMh1VrVd3uPDVlqmsOYBJw+x1i3OJyykoNYcUzGAX1jv0x7pLF9tbHJdZp3Gpszjqp3K9/SoQsNGdcFUxwhdBa6xOY6XSsHVD8pgpMJ+Qbs6cPw9idZpzVupJqx97XdZidZQZqryfDr3tJSYqnhkd+CrGW5Q2wE687GA/YgO1qt0kpOuEBTRtWcrmoHJ8Cwexq13tRVBAomG4hMtkfo5yfUchPXqtzAtU0vAe1ufdeIaMIYRP0z1utYX8yPnSaS7YetDuz+PkQcscgs6GvreYVDUhaEAWtEJIRaiQPpo2spOL1RBPwv6cPO/bkgjIo7Zg4clUFI2GyHKYfPvdhAlfaHcEkurKbTdWC0Kq4Y7JByWPjmxO8tBIx5DKaT6/LPAJnWK23DF4EtM4zqjMGS/3Mjtzi/xTsi+2+TLmDPnwF4bbrTr5d+U64ow+7TBTIDoA/c4G637VaJRDZqEwZUN+pSe/zX6YVPnsdPwL7wY/3Bxx9wGsk3G+jp3k7EoRr+Bgx5ae5Ltyp9j/88P20qpeVJB31mcIFZ3safnsAi5KSanpI5Za1YEptGih27LPtUD9x83tFgJd84wKTbNBneHxBAUE14AVE5xF8lWPMiIXdFtX8Lq3HX99kRipmWriMqVLpghR5+AbRlU5DDjhRJBVwkujVo5WXulMF2s/Pg5zMfPfUKGymLiiEGmctCqGHVotitkRPN6WMEOQuGfNcxlUBiCBMnxWYALtPH6ahLFENUFGjKgRPUUow7EfbgpC89v1ZplV9+WnSEf5Lnf6zVAXaTJhFT1aCrRoowSBjLKZrNE9pbF0jb73zRZIOGorE81GKo2+FAJSGK7QpZoNtiAaN32dlzStcZcb94BdWmjx/b9dSMX4SdoxxBXd8G8QhkcBvs9LoJuNqMRKxN5KXIsu0bBq4AlfK2oFhLUcXyQppW23lQsamkWpGRrfAnW+3jJ9czCjK9TxTSgOlhFO2T73MoiCNMuSOG+1gEh0nmiUtE1opEA51EPdl0qOQ7ZGG1F5TdMmEubRORwHMQg3Iq6aWQ7LEojOBoIUFiux3IhKUMxIsach9KBobJ+I3aJDjh5khIfxQurFgTtiNYaKWGO5KlVapB69pF1b+jQaJcGHYxlPqG8JtS1t+i2OOOa05CHIjjlTdhLr07aQD4ToTkWsmuBJUwcOOclN1PiEYgiRP4U4wSZb0MMC/3gcD2G4ZBjolSTAQEuhF3q6PLzIdJAKgb7qEKA5Mg0EoaYFjm2DqOZaYTim00NboyvAGfdCkv8pw5bQhmWfLm3isbBlvW6NP2MfA8KfE1adHib6ib5RB15rd6JaqjlNu0ocjAY6lTSmX6e44Un7cuQvrokrStmVsDlsV1ScLo6lJxaAsMYruA/mQ09PC56+nU8tow7bc/6f/Zg5epjZR8kbWpEXKWIHRTgs9BwES3ERl+bf3vzFeV9pId2zW3F1b0hQfjF/RUpszNwUG2wbEhTXgjnrmSh00JOljnPS57EBC7SjvMUXjX14VoPB/el3zP72u+a+van7U1lHZM65jakclX3WrDcl51FogLIM7a/PMstZ9OEeVGNkjNlv2b/BC9m8eNrAdE0N00xs0CVyj8SHrKaWqvFHLmc7WVN48XsdInWfs6a7NWV9JwVt+kLWkYT4GNC9DWznjw4qb6hW4MOZPMdnIFriTgvMjKOQZJFKp4OyxPabtgwBmwaFRTM0Xv7M/cPFc62pfy4ameqGLQLDeWBblsG8ddMAyop0RCTqF0OayxLMEb/e05EYi2sGryhNkCsKGCqY8UUDz3yA642Vhy0hMfModQ4eTnGGHgvO+JVkn7m2aRouk0ZdPXJ2Grot7tKg14KOTrZqkF0qhrnYQTgje2HBYs5Is0zVNZl2Ew72JmANXCmgUOTYJ+6dVQEEoWMurGcACx1CLFlT6Q9TYMqpKiL6nLOTUPAr3QoWbE9qj0AoJHrPOLGwYMVbt92s1XrWAKkla5VRz4nXZn63YzG5m8kentKQO3v/nb6wAIf2RsA+ZoPg5nMQvoK7pV4ucqdclM6pKB19FgdZvdMM4O03JCFqmAtJ0klV6bhzzT/kZ+awPKys47fELmgRlsvLh6JJXlTRRVw5EdF3sQZXaCElbcLRzXILQGNCbMuu466auGpf4JNrunjUePPZvHz8zoc2MCBi0V4roviyNxbq0TEBWiUCjk1frDMZlBlPvXxREatEvCTqicPRQgFsKzEpOSuBHFpR0ehSE9pZZq+dHImq1sgjDdbVUzyltbUEVM2203eEriX3atvWNAixeBVv+P788/vq/VBCfMsXFDJsYH9Nvyv64I0oMLTE0tRdbTpU7uCi6U3tj2QmMx9lloxe6IamGHlY4HCHXUi1m3hC5iXia42iE7GtomtzUiWT1fWmtTwMMMvKjqH43a26p9h/KD33L68P31Zyk9ZF2HxrtHbfP4yqp3tIlRaI/++pHKdURjLzJYcfMiAhVsXGAqynHtyS/E0oUL7XmxQhxY5pnGu1899QAargF6kk/YnXSwazt4M9PvJbFPgLYPZo9btrPn5j3i9PPbHI60vaFauBPH/+rzzossxli2CJbMSDSctDScOEToRSx4I6Ini55KF9D+vQhnNxOEfQOPxXrsa46KUn0rU8ffc65MrxhpeGVp2FDjcKC7tKStR4qQnJhxKeXoO3UUJmBj5BWYxmfXSABWxK1EdKQmVJD5tbASerOhhtKS4GutjT22GvyUHM7RXd6ZUf6ZO0ATxLLRUYmt1IwgtpVSPtMCtukfb6pWC03Q8p+s5PIg57kKYKkpfqRGkgnazWoqi+v73e+rDkthmpB9bnjpVPijqidnH3+PLcjYrWNBYGEI1UaLqSzfRRQGWLaLND/oDxrueI9LVPudX1jEg7Vs6GVNKHX5o0vy9Ala6DR5oL88V//Mo1bfNrlHrc9ZF2iGRQgZOHzXZM+7orScQabonRcHXHk1Mo4lI/NuHBgUhJmA4tH6P1eGR7kLKdrOZ7OyZJklp1jUjkwJRcraRPRkOwyhU3jgtuJzKPWJOwcznyxZTiGi9RF4CItnL3hLpNrOnGPTadGV+l6xaf6T5/WuZZutpKkFdeyZOOTlTOXbu8k7aBz5XQFZbFMVu+pfIaaFBnEJkvBNBoJEbFS4mwTalExKzyUkBA3B62FTLGuCyJ703VBZXAIZXfsZ8Gh8Z4tv9ceAmucTS6152DaNLS4PXRV6+qNHbfOj56INAxNMbGvCcxOhLs7Qkl/e4SbCpy/yJNnfa6ELA0nhUK3i8vO3NGK7sa1vKH9SjrAd36n15nIIvKfyHvmcg5a0+A4OsDEILA98ClbkKJp80uW2xQAI15d+sapgHlBaWstiI7qHCIlX9Yez9syISPIGJzWVicYykKMbqQVHeJERsOHumXSGvNwv9DXnSPXSAm+q5xGUvlwXofhqxIm/mN0Rk2C0vyMeiOUFlDyrnaPd+BGbOqJ5nIaysdiVLDrgS4Gb14IItNZLWY20Mm33NozGVKDcpba+KN2L0ObArG7muOd3w1ixeqZWviQSu3u2Y7E+RNq50o7vhQ8CrxONN6SZ4byQp3rJw9Z5E2D9tkmEJckGNt6XjMrDdl20BJv6WC7jtfyb5tu6fiUFu2giF5pQj4STaSxf6pj+UjUEDPJETOv0hR/0k8db55MXxqrPnx9DdaMLuIOzJ6YTc4c01I9Lm7UK5Jlo5h35olC4FNyWRNrYibhTpSwdEgmFS2mlupWSH0i+f1od6zh4rhyFpkn1DbJbBreXk3H+bwX8VS9P/aOerBahvHqzPx1ncAeiJnpPtdtEdYXUt0WvhFrWsbvZEw37O/igr4dLo62DkPy27JvHe9fCsgFDUtCPRqcFqT4tEh2z27kpOnOs/f+G5kHIjK1XAcB+XapDmogOfmk62I1+eTjBZI3zVMMGz1qQS2zjkeoTx9XmIZ30cQ73jMPPX9MS2rhamJaMjyS8q0D6/pCl/Q6n5e3Uu9iiafKoUh8nXyld3lIriq2iRdypAo5ljm5/TvYDKrSvuE0bz7NpGH76RMMKZmxdGeFCOYh57p6xujRhV5FsvWk9fB1T0wUx+zwKiEzwC3tNlyWwmIFKO1zfTwK8tHf6u27WlpyJm3KpUKqHiWtV2JSMysJF7ZkVw4d7fpwTDPZ7pBYRmf98UpO7WutKst6ZjxCZpLd5chM8FRUIB2FDnMQ/X/KPnWGZFmf/+OJtVoqr6C+7HA5LxRo/h0XC3LVtG9svFbwcyGtv1G7WsZ7X4ZlrKQbsyyBrlK51NRPLpRatTSJdTqltVrx7BpTj8J35tk3Fq06cjHikMCP5UYoQJbLb3oSCXd+enKrxlQB6eWjoBwhkLHgXxEY3+noh0y71u1f9JYiyl96gWjtQrRsqrtvffhIXTa8ghsXQOrinlP3pOazk/dbZ+574uqlRzp7/3L90CEWulN6OB992V2wiRh6n7lNosrOP9yo9HJG+X5OcSuhHINpkjPoI6ACanAr5a6hyn4id1w/vvquX17LujakBYqfFbMuvKA3im8IUg0/T68MWGc6/+TFvJu7exk99DKXO7kqvy65fzyyU/LlWo9xTkEw+xG//pbJ9vTP/t9/eZsyOksv0A1PrhImSX56NTt7jY8MPeQd5k/2Lj/GGx7yDU+vpQcbHxbGNjxH914xbQofk9TxTTcXdSCNgRkQIPsEVPZOKQY1vaQzGAg3+pxGcAw6Ex6uK7TwMWh8eTG8GS9tj3ey9I+dGJOFiuklhsQe0ysa/k0mbbDNF6lE3RWwN/y8j8NNb933ckZv3Y8fJj1zo6Sq7lxlHO1ufJi6ssiofamv+Z+i+Atwlx4LiiMNa5e9qjh503H4GxeR2nlh6biOq8L/rr8eW8AJat36LAD+soBDNxTjtJ1ptY0PnY2eAK5Ax7PPKZotThSn6Zukv7rhBwilVOm1W6HVCZT0mUKpmOAW2EV3sTZuCDdAGSmOw3Z3NoR0SbqPuKRiv+vKOm6P/g1gxf5ac+uksMCNOGajRyWowPbPAaVH15ef7kLHLhUot1fE1xPGrzwOJW1xV4PU2dPi0l2+b0/SXaadGKikVt+1myByNhvdKWcue2n1nlqfmvf2W5DDnv74d1+oOnv+XY94b6+hoPc+wto2H4xypesK8GZRc+d/2D38XwAAAP//nE7x5g==" } diff --git a/docs/devguide/modules-dev-guide.asciidoc b/docs/devguide/modules-dev-guide.asciidoc index b3a8cb22592..0936438900e 100644 --- a/docs/devguide/modules-dev-guide.asciidoc +++ b/docs/devguide/modules-dev-guide.asciidoc @@ -304,10 +304,9 @@ variables to dynamically switch between configurations. [float] ==== ingest/*.json -The `ingest/` folder contains Elasticsearch -{ref}/ingest.html[Ingest Node] pipeline configurations. The Ingest -Node pipelines are responsible for parsing the log lines and doing other -manipulations on the data. +The `ingest/` folder contains {es} {ref}/ingest.html[ingest pipeline] +configurations. Ingest pipelines are responsible for parsing the log lines and +doing other manipulations on the data. The files in this folder are JSON or YAML documents representing {ref}/pipeline.html[pipeline definitions]. Just like with the `config/` @@ -344,10 +343,10 @@ on_failure: ---- From here, you would typically add processors to the `processors` array to do -the actual parsing. For details on how to use ingest node processors, see the -{ref}/ingest-processors.html[ingest node documentation]. In +the actual parsing. For information about available ingest processors, see the +{ref}/processors.html[processor reference documentation]. In particular, you will likely find the -{ref}/grok-processor.html[Grok processor] to be useful for parsing. +{ref}/grok-processor.html[grok processor] to be useful for parsing. Here is an example for parsing the Nginx access logs. [source,json] diff --git a/filebeat/_meta/config/filebeat.inputs.reference.yml.tmpl b/filebeat/_meta/config/filebeat.inputs.reference.yml.tmpl index 211292b9432..f7e0dc79fc7 100644 --- a/filebeat/_meta/config/filebeat.inputs.reference.yml.tmpl +++ b/filebeat/_meta/config/filebeat.inputs.reference.yml.tmpl @@ -168,7 +168,7 @@ filebeat.inputs: # this can mean that the first entries of a new file are skipped. #tail_files: false - # The Ingest Node pipeline ID associated with this input. If this is set, it + # The ingest pipeline ID associated with this input. If this is set, it # overwrites the pipeline option from the Elasticsearch output. #pipeline: @@ -351,7 +351,7 @@ filebeat.inputs: # carriage_return, carriage_return_line_feed, next_line, line_separator, paragraph_separator. #line_terminator: auto - # The Ingest Node pipeline ID associated with this input. If this is set, it + # The ingest pipeline ID associated with this input. If this is set, it # overwrites the pipeline option from the Elasticsearch output. #pipeline: diff --git a/filebeat/beater/filebeat.go b/filebeat/beater/filebeat.go index 435161bb9f4..43edc32ff3f 100644 --- a/filebeat/beater/filebeat.go +++ b/filebeat/beater/filebeat.go @@ -58,9 +58,9 @@ import ( _ "github.com/elastic/beats/v7/filebeat/autodiscover" ) -const pipelinesWarning = "Filebeat is unable to load the Ingest Node pipelines for the configured" + +const pipelinesWarning = "Filebeat is unable to load the ingest pipelines for the configured" + " modules because the Elasticsearch output is not configured/enabled. If you have" + - " already loaded the Ingest Node pipelines or are using Logstash pipelines, you" + + " already loaded the ingest pipelines or are using Logstash pipelines, you" + " can ignore this warning." var ( diff --git a/filebeat/docs/filebeat-modules-options.asciidoc b/filebeat/docs/filebeat-modules-options.asciidoc index 80b87e14f12..bf404588c03 100644 --- a/filebeat/docs/filebeat-modules-options.asciidoc +++ b/filebeat/docs/filebeat-modules-options.asciidoc @@ -13,7 +13,7 @@ a log type that isn't supported, or you want to use a different setup. {beatname_uc} <<{beatname_lc}-modules,modules>> provide a quick way to get started processing common log formats. They contain default configurations, -{es} ingest node pipeline definitions, and {kib} dashboards to help you +{es} ingest pipeline definitions, and {kib} dashboards to help you implement and deploy a log monitoring solution. You can configure modules in the `modules.d` directory (recommended), or in the diff --git a/filebeat/docs/include/what-happens.asciidoc b/filebeat/docs/include/what-happens.asciidoc index f6e30d8e6c0..9d736c923ea 100644 --- a/filebeat/docs/include/what-happens.asciidoc +++ b/filebeat/docs/include/what-happens.asciidoc @@ -5,8 +5,8 @@ defaults) * Makes sure each multiline log event gets sent as a single event -* Uses ingest node to parse and process the log lines, shaping the data into a structure suitable -for visualizing in Kibana +* Uses an {es} ingest pipeline to parse and process the log lines, shaping the +data into a structure suitable for visualizing in Kibana ifeval::["{has-dashboards}"=="true"] * Deploys dashboards for visualizing the log data diff --git a/filebeat/docs/inputs/input-common-options.asciidoc b/filebeat/docs/inputs/input-common-options.asciidoc index de22a519846..eaa1ffe6ac8 100644 --- a/filebeat/docs/inputs/input-common-options.asciidoc +++ b/filebeat/docs/inputs/input-common-options.asciidoc @@ -77,7 +77,7 @@ processors in your config. [float] ===== `pipeline` -The Ingest Node pipeline ID to set for the events generated by this input. +The ingest pipeline ID to set for the events generated by this input. NOTE: The pipeline ID can also be configured in the Elasticsearch output, but this option usually results in simpler configuration files. If the pipeline is diff --git a/filebeat/docs/modules-overview.asciidoc b/filebeat/docs/modules-overview.asciidoc index 008a16c0d87..0df2d3cc3ee 100644 --- a/filebeat/docs/modules-overview.asciidoc +++ b/filebeat/docs/modules-overview.asciidoc @@ -13,7 +13,7 @@ the following: The {beatname_uc} configuration is also responsible with stitching together multiline events when needed. -* {es} {ref}/ingest.html[Ingest Node] pipeline definition, +* {es} {ref}/ingest.html[ingest pipeline] definition, which is used to parse the log lines. * Fields definitions, which are used to configure {es} with the diff --git a/filebeat/docs/modules/iptables.asciidoc b/filebeat/docs/modules/iptables.asciidoc index ef00ffbec75..7456e823dd2 100644 --- a/filebeat/docs/modules/iptables.asciidoc +++ b/filebeat/docs/modules/iptables.asciidoc @@ -22,8 +22,8 @@ When you run the module, it performs a few tasks under the hood: * Sets the default input to `syslog` and binds to `localhost` port `9001` (but don’t worry, you can override the defaults). -* Uses ingest node to parse and process the log lines, shaping the data into - a structure suitable for visualizing in Kibana. +* Uses an ingest pipeline to parse and process the log lines, shaping the data + into a structure suitable for visualizing in Kibana. * Deploys dashboards for visualizing the log data. diff --git a/filebeat/docs/modules/netflow.asciidoc b/filebeat/docs/modules/netflow.asciidoc index c88ee88418a..4d4368a624e 100644 --- a/filebeat/docs/modules/netflow.asciidoc +++ b/filebeat/docs/modules/netflow.asciidoc @@ -18,7 +18,7 @@ NetFlow versions older than 9, fields are mapped automatically to NetFlow v9. This module wraps the <> to enrich the flow records with geolocation information about the IP endpoints by using -Elasticsearch Ingest Node. +an {es} ingest pipeline. include::../include/gs-link.asciidoc[] diff --git a/filebeat/filebeat.reference.yml b/filebeat/filebeat.reference.yml index 33a24a5fb9c..055de812f9c 100644 --- a/filebeat/filebeat.reference.yml +++ b/filebeat/filebeat.reference.yml @@ -575,7 +575,7 @@ filebeat.inputs: # this can mean that the first entries of a new file are skipped. #tail_files: false - # The Ingest Node pipeline ID associated with this input. If this is set, it + # The ingest pipeline ID associated with this input. If this is set, it # overwrites the pipeline option from the Elasticsearch output. #pipeline: @@ -758,7 +758,7 @@ filebeat.inputs: # carriage_return, carriage_return_line_feed, next_line, line_separator, paragraph_separator. #line_terminator: auto - # The Ingest Node pipeline ID associated with this input. If this is set, it + # The ingest pipeline ID associated with this input. If this is set, it # overwrites the pipeline option from the Elasticsearch output. #pipeline: @@ -1391,7 +1391,7 @@ output.elasticsearch: # In case you modify this pattern you must update setup.template.name and setup.template.pattern accordingly. #index: "filebeat-%{[agent.version]}-%{+yyyy.MM.dd}" - # Optional ingest node pipeline. By default no pipeline will be used. + # Optional ingest pipeline. By default no pipeline will be used. #pipeline: "" # Optional HTTP path diff --git a/heartbeat/_meta/config/beat.reference.yml.tmpl b/heartbeat/_meta/config/beat.reference.yml.tmpl index 67145c7ac21..bfff82681ce 100644 --- a/heartbeat/_meta/config/beat.reference.yml.tmpl +++ b/heartbeat/_meta/config/beat.reference.yml.tmpl @@ -148,7 +148,7 @@ heartbeat.monitors: # Required TLS protocols #supported_protocols: ["TLSv1.0", "TLSv1.1", "TLSv1.2"] - # The Ingest Node pipeline ID associated with this input. If this is set, it + # The ingest pipeline ID associated with this input. If this is set, it # overwrites the pipeline option from the Elasticsearch output. #pipeline: @@ -235,7 +235,7 @@ heartbeat.monitors: # equals: # myField: expectedValue - # The Ingest Node pipeline ID associated with this input. If this is set, it + # The ingest pipeline ID associated with this input. If this is set, it # overwrites the pipeline option from the Elasticsearch output. #pipeline: diff --git a/heartbeat/docs/monitors/monitor-common-options.asciidoc b/heartbeat/docs/monitors/monitor-common-options.asciidoc index 3d22b4e4b0f..8d14e8adb51 100644 --- a/heartbeat/docs/monitors/monitor-common-options.asciidoc +++ b/heartbeat/docs/monitors/monitor-common-options.asciidoc @@ -147,7 +147,7 @@ processors in your config. [[monitor-pipeline]] ===== `pipeline` -The Ingest Node pipeline ID to set for the events generated by this input. +The {es} ingest pipeline ID to set for the events generated by this input. NOTE: The pipeline ID can also be configured in the Elasticsearch output, but this option usually results in simpler configuration files. If the pipeline is diff --git a/heartbeat/heartbeat.reference.yml b/heartbeat/heartbeat.reference.yml index 195abe806cc..0a7bec03b61 100644 --- a/heartbeat/heartbeat.reference.yml +++ b/heartbeat/heartbeat.reference.yml @@ -148,7 +148,7 @@ heartbeat.monitors: # Required TLS protocols #supported_protocols: ["TLSv1.0", "TLSv1.1", "TLSv1.2"] - # The Ingest Node pipeline ID associated with this input. If this is set, it + # The ingest pipeline ID associated with this input. If this is set, it # overwrites the pipeline option from the Elasticsearch output. #pipeline: @@ -235,7 +235,7 @@ heartbeat.monitors: # equals: # myField: expectedValue - # The Ingest Node pipeline ID associated with this input. If this is set, it + # The ingest pipeline ID associated with this input. If this is set, it # overwrites the pipeline option from the Elasticsearch output. #pipeline: @@ -625,7 +625,7 @@ output.elasticsearch: # In case you modify this pattern you must update setup.template.name and setup.template.pattern accordingly. #index: "heartbeat-%{[agent.version]}-%{+yyyy.MM.dd}" - # Optional ingest node pipeline. By default no pipeline will be used. + # Optional ingest pipeline. By default no pipeline will be used. #pipeline: "" # Optional HTTP path diff --git a/journalbeat/journalbeat.reference.yml b/journalbeat/journalbeat.reference.yml index fa09de1a9fb..322429ae687 100644 --- a/journalbeat/journalbeat.reference.yml +++ b/journalbeat/journalbeat.reference.yml @@ -422,7 +422,7 @@ output.elasticsearch: # In case you modify this pattern you must update setup.template.name and setup.template.pattern accordingly. #index: "journalbeat-%{[agent.version]}-%{+yyyy.MM.dd}" - # Optional ingest node pipeline. By default no pipeline will be used. + # Optional ingest pipeline. By default no pipeline will be used. #pipeline: "" # Optional HTTP path diff --git a/libbeat/_meta/config/output-elasticsearch.reference.yml.tmpl b/libbeat/_meta/config/output-elasticsearch.reference.yml.tmpl index 8bb01212d2d..943e6a16b47 100644 --- a/libbeat/_meta/config/output-elasticsearch.reference.yml.tmpl +++ b/libbeat/_meta/config/output-elasticsearch.reference.yml.tmpl @@ -36,7 +36,7 @@ output.elasticsearch: # In case you modify this pattern you must update setup.template.name and setup.template.pattern accordingly. #index: "{{.BeatIndexPrefix}}-%{[agent.version]}-%{+yyyy.MM.dd}" - # Optional ingest node pipeline. By default no pipeline will be used. + # Optional ingest pipeline. By default no pipeline will be used. #pipeline: "" # Optional HTTP path diff --git a/libbeat/docs/monitoring/monitoring-metricbeat.asciidoc b/libbeat/docs/monitoring/monitoring-metricbeat.asciidoc index 47168cc1870..562bb0b618b 100644 --- a/libbeat/docs/monitoring/monitoring-metricbeat.asciidoc +++ b/libbeat/docs/monitoring/monitoring-metricbeat.asciidoc @@ -259,8 +259,8 @@ If you configured the monitoring cluster to use encrypted communications, you must access it via HTTPS. For example, use a `hosts` setting like `https://es-mon-1:9200`. -IMPORTANT: The {es} {monitor-features} use ingest pipelines, therefore the -cluster that stores the monitoring data must have at least one ingest node. +IMPORTANT: The {es} {monitor-features} use ingest pipelines. The cluster that +stores the monitoring data must have at least one node with the `ingest` role. If the {es} {security-features} are enabled on the monitoring cluster, you must provide a valid user ID and password so that {metricbeat} can send metrics diff --git a/libbeat/docs/shared-config-ingest.asciidoc b/libbeat/docs/shared-config-ingest.asciidoc index 7f661f3921a..178c4b666fb 100644 --- a/libbeat/docs/shared-config-ingest.asciidoc +++ b/libbeat/docs/shared-config-ingest.asciidoc @@ -10,20 +10,20 @@ ////////////////////////////////////////////////////////////////////////// [[configuring-ingest-node]] -== Parse data by using ingest node +== Parse data using an ingest pipeline -When you use Elasticsearch for output, you can configure {beatname_uc} to use -{ref}/ingest.html[ingest node] to pre-process documents before the actual -indexing takes place in Elasticsearch. +When you use {es} for output, you can configure {beatname_uc} to use +an {ref}/ingest.html[ingest pipeline] to pre-process documents before the actual +indexing takes place in {es}. ifndef::no-output-logstash[] -Ingest node is a convenient processing option when you want to do some extra -processing on your data, but you do not require the full power of Logstash. +An ingest pipeline is a convenient processing option when you want to do some +extra processing on your data, but you do not require the full power of {ls}. endif::[] -For example, you can create an ingest node pipeline -in Elasticsearch that consists of one processor that removes a field in a +For example, you can create an ingest pipeline +in {es} that consists of one processor that removes a field in a document followed by another processor that renames a field. -After defining the pipeline in Elasticsearch, you simply configure {beatname_uc} +After defining the pipeline in {es}, you simply configure {beatname_uc} to use the pipeline. To configure {beatname_uc}, you specify the pipeline ID in the `parameters` option under `elasticsearch` in the +{beatname_lc}.yml+ file: @@ -51,7 +51,7 @@ named `pipeline.json`: } ------------------------------------------------------------------------------ -To add the pipeline in Elasticsearch, you would run: +To add the pipeline in {es}, you would run: [source,shell] ------------------------------------------------------------------------------ @@ -70,4 +70,4 @@ output.elasticsearch: When you run {beatname_uc}, the value of `agent.name` is converted to lowercase before indexing. For more information about defining a pre-processing pipeline, see the -{ref}/ingest.html[Ingest Node] documentation. +{ref}/ingest.html[ingest pipeline] documentation. diff --git a/libbeat/docs/shared-geoip.asciidoc b/libbeat/docs/shared-geoip.asciidoc index 454f9afbe31..522b451f027 100644 --- a/libbeat/docs/shared-geoip.asciidoc +++ b/libbeat/docs/shared-geoip.asciidoc @@ -30,7 +30,7 @@ endif::no-output-logstash[] To configure {beatname_uc} and the `geoip` processor: -1. Define an ingest node pipeline that uses one or more `geoip` processors to +1. Define an ingest pipeline that uses one or more `geoip` processors to add location information to the event. For example, you can use the Console in {kib} to create the following pipeline: + diff --git a/libbeat/outputs/elasticsearch/docs/elasticsearch.asciidoc b/libbeat/outputs/elasticsearch/docs/elasticsearch.asciidoc index ebe22854bee..2f9f709d2fb 100644 --- a/libbeat/outputs/elasticsearch/docs/elasticsearch.asciidoc +++ b/libbeat/outputs/elasticsearch/docs/elasticsearch.asciidoc @@ -429,7 +429,7 @@ ifndef::no-pipeline[] [[pipeline-option-es]] ===== `pipeline` -A format string value that specifies the ingest node pipeline to write events to. +A format string value that specifies the ingest pipeline to write events to. ["source","yaml"] ------------------------------------------------------------------------------ @@ -441,7 +441,7 @@ output.elasticsearch: For more information, see <>. ifndef::apm-server[] -You can set the ingest node pipeline dynamically by using a format string to +You can set the ingest pipeline dynamically by using a format string to access any event field. For example, this configuration uses a custom field, `fields.log_type`, to set the pipeline for each event: @@ -458,7 +458,7 @@ pipeline named `critical_pipeline`. endif::apm-server[] ifdef::apm-server[] -You can set the ingest node pipeline dynamically by using a format string to +You can set the ingest pipeline dynamically by using a format string to access any event field. For example, this configuration uses the field, `processor.event`, to set the pipeline for each event: @@ -481,12 +481,12 @@ TIP: To learn how to add custom fields to events, see the <> option. See the <> setting for other ways to set the -ingest node pipeline dynamically. +ingest pipeline dynamically. [[pipelines-option-es]] ===== `pipelines` -An array of pipeline selector rules. Each rule specifies the ingest node +An array of pipeline selector rules. Each rule specifies the ingest pipeline to use for events that match the rule. During publishing, {beatname_uc} uses the first matching rule in the array. Rules can contain conditionals, format string-based fields, and name mappings. If the `pipelines` setting is @@ -613,7 +613,7 @@ pipeline named `error_pipeline`, etc. NOTE: Defining any pipeline will deactivate the default `apm` pipeline. endif::apm-server[] -For more information about ingest node pipelines, see +For more information about ingest pipelines, see <>. endif::[] diff --git a/metricbeat/metricbeat.reference.yml b/metricbeat/metricbeat.reference.yml index f293bb5bdd3..96ad7003fa1 100644 --- a/metricbeat/metricbeat.reference.yml +++ b/metricbeat/metricbeat.reference.yml @@ -1292,7 +1292,7 @@ output.elasticsearch: # In case you modify this pattern you must update setup.template.name and setup.template.pattern accordingly. #index: "metricbeat-%{[agent.version]}-%{+yyyy.MM.dd}" - # Optional ingest node pipeline. By default no pipeline will be used. + # Optional ingest pipeline. By default no pipeline will be used. #pipeline: "" # Optional HTTP path diff --git a/packetbeat/packetbeat.reference.yml b/packetbeat/packetbeat.reference.yml index 09dfd0e2e00..49b148eb80f 100644 --- a/packetbeat/packetbeat.reference.yml +++ b/packetbeat/packetbeat.reference.yml @@ -974,7 +974,7 @@ output.elasticsearch: # In case you modify this pattern you must update setup.template.name and setup.template.pattern accordingly. #index: "packetbeat-%{[agent.version]}-%{+yyyy.MM.dd}" - # Optional ingest node pipeline. By default no pipeline will be used. + # Optional ingest pipeline. By default no pipeline will be used. #pipeline: "" # Optional HTTP path diff --git a/winlogbeat/winlogbeat.reference.yml b/winlogbeat/winlogbeat.reference.yml index 02cad937767..1b0e3e79c3e 100644 --- a/winlogbeat/winlogbeat.reference.yml +++ b/winlogbeat/winlogbeat.reference.yml @@ -402,7 +402,7 @@ output.elasticsearch: # In case you modify this pattern you must update setup.template.name and setup.template.pattern accordingly. #index: "winlogbeat-%{[agent.version]}-%{+yyyy.MM.dd}" - # Optional ingest node pipeline. By default no pipeline will be used. + # Optional ingest pipeline. By default no pipeline will be used. #pipeline: "" # Optional HTTP path diff --git a/x-pack/auditbeat/auditbeat.reference.yml b/x-pack/auditbeat/auditbeat.reference.yml index 21cfc709046..b478846f564 100644 --- a/x-pack/auditbeat/auditbeat.reference.yml +++ b/x-pack/auditbeat/auditbeat.reference.yml @@ -535,7 +535,7 @@ output.elasticsearch: # In case you modify this pattern you must update setup.template.name and setup.template.pattern accordingly. #index: "auditbeat-%{[agent.version]}-%{+yyyy.MM.dd}" - # Optional ingest node pipeline. By default no pipeline will be used. + # Optional ingest pipeline. By default no pipeline will be used. #pipeline: "" # Optional HTTP path diff --git a/x-pack/dockerlogbeat/docs/configuration.asciidoc b/x-pack/dockerlogbeat/docs/configuration.asciidoc index e8d398b0b87..8cacb97ae73 100644 --- a/x-pack/dockerlogbeat/docs/configuration.asciidoc +++ b/x-pack/dockerlogbeat/docs/configuration.asciidoc @@ -100,7 +100,7 @@ you can use API keys to secure communication with {es}. |`pipeline` | -|A format string value that specifies the ingest node pipeline to write events to. +|A format string value that specifies the {es} ingest pipeline to write events to. |`timeout` |`90` diff --git a/x-pack/filebeat/filebeat.reference.yml b/x-pack/filebeat/filebeat.reference.yml index 2fc7721ea27..7fcb4efaa68 100644 --- a/x-pack/filebeat/filebeat.reference.yml +++ b/x-pack/filebeat/filebeat.reference.yml @@ -2514,7 +2514,7 @@ filebeat.inputs: # this can mean that the first entries of a new file are skipped. #tail_files: false - # The Ingest Node pipeline ID associated with this input. If this is set, it + # The ingest pipeline ID associated with this input. If this is set, it # overwrites the pipeline option from the Elasticsearch output. #pipeline: @@ -2697,7 +2697,7 @@ filebeat.inputs: # carriage_return, carriage_return_line_feed, next_line, line_separator, paragraph_separator. #line_terminator: auto - # The Ingest Node pipeline ID associated with this input. If this is set, it + # The ingest pipeline ID associated with this input. If this is set, it # overwrites the pipeline option from the Elasticsearch output. #pipeline: @@ -3479,7 +3479,7 @@ output.elasticsearch: # In case you modify this pattern you must update setup.template.name and setup.template.pattern accordingly. #index: "filebeat-%{[agent.version]}-%{+yyyy.MM.dd}" - # Optional ingest node pipeline. By default no pipeline will be used. + # Optional ingest pipeline. By default no pipeline will be used. #pipeline: "" # Optional HTTP path diff --git a/x-pack/filebeat/module/iptables/_meta/docs.asciidoc b/x-pack/filebeat/module/iptables/_meta/docs.asciidoc index 68c8bf72133..10cf274fa89 100644 --- a/x-pack/filebeat/module/iptables/_meta/docs.asciidoc +++ b/x-pack/filebeat/module/iptables/_meta/docs.asciidoc @@ -17,8 +17,8 @@ When you run the module, it performs a few tasks under the hood: * Sets the default input to `syslog` and binds to `localhost` port `9001` (but don’t worry, you can override the defaults). -* Uses ingest node to parse and process the log lines, shaping the data into - a structure suitable for visualizing in Kibana. +* Uses an ingest pipeline to parse and process the log lines, shaping the data + into a structure suitable for visualizing in Kibana. * Deploys dashboards for visualizing the log data. diff --git a/x-pack/filebeat/module/netflow/_meta/docs.asciidoc b/x-pack/filebeat/module/netflow/_meta/docs.asciidoc index cddf5e6fc24..e3c101c4ec3 100644 --- a/x-pack/filebeat/module/netflow/_meta/docs.asciidoc +++ b/x-pack/filebeat/module/netflow/_meta/docs.asciidoc @@ -13,7 +13,7 @@ NetFlow versions older than 9, fields are mapped automatically to NetFlow v9. This module wraps the <> to enrich the flow records with geolocation information about the IP endpoints by using -Elasticsearch Ingest Node. +an {es} ingest pipeline. include::../include/gs-link.asciidoc[] diff --git a/x-pack/functionbeat/docs/overview.asciidoc b/x-pack/functionbeat/docs/overview.asciidoc index 132028d3b36..88e8dc52dbd 100644 --- a/x-pack/functionbeat/docs/overview.asciidoc +++ b/x-pack/functionbeat/docs/overview.asciidoc @@ -48,7 +48,7 @@ a Cloudwatch Log group. . {beats} processors, such as <> and <>, filter and structure the events. -. Optional {ref}/ingest.html[ingest node] pipelines in {es} further enhance the +. Optional {ref}/ingest.html[ingest pipelines] in {es} further enhance the data. . The structured events are indexed into an {es} cluster. @@ -86,7 +86,7 @@ application events. . The {beats} <> processor decodes JSON strings and replaces them with valid JSON objects. -. Optional {ref}/ingest.html[ingest node] pipelines in {es} further enhance the +. Optional {ref}/ingest.html[ingest pipelines] in {es} further enhance the data. . The events are indexed into an {es} cluster. diff --git a/x-pack/functionbeat/functionbeat.reference.yml b/x-pack/functionbeat/functionbeat.reference.yml index cb751703f0c..5531351df49 100644 --- a/x-pack/functionbeat/functionbeat.reference.yml +++ b/x-pack/functionbeat/functionbeat.reference.yml @@ -765,7 +765,7 @@ output.elasticsearch: # In case you modify this pattern you must update setup.template.name and setup.template.pattern accordingly. #index: "functionbeat-%{[agent.version]}-%{+yyyy.MM.dd}" - # Optional ingest node pipeline. By default no pipeline will be used. + # Optional ingest pipeline. By default no pipeline will be used. #pipeline: "" # Optional HTTP path diff --git a/x-pack/heartbeat/heartbeat.reference.yml b/x-pack/heartbeat/heartbeat.reference.yml index 195abe806cc..0a7bec03b61 100644 --- a/x-pack/heartbeat/heartbeat.reference.yml +++ b/x-pack/heartbeat/heartbeat.reference.yml @@ -148,7 +148,7 @@ heartbeat.monitors: # Required TLS protocols #supported_protocols: ["TLSv1.0", "TLSv1.1", "TLSv1.2"] - # The Ingest Node pipeline ID associated with this input. If this is set, it + # The ingest pipeline ID associated with this input. If this is set, it # overwrites the pipeline option from the Elasticsearch output. #pipeline: @@ -235,7 +235,7 @@ heartbeat.monitors: # equals: # myField: expectedValue - # The Ingest Node pipeline ID associated with this input. If this is set, it + # The ingest pipeline ID associated with this input. If this is set, it # overwrites the pipeline option from the Elasticsearch output. #pipeline: @@ -625,7 +625,7 @@ output.elasticsearch: # In case you modify this pattern you must update setup.template.name and setup.template.pattern accordingly. #index: "heartbeat-%{[agent.version]}-%{+yyyy.MM.dd}" - # Optional ingest node pipeline. By default no pipeline will be used. + # Optional ingest pipeline. By default no pipeline will be used. #pipeline: "" # Optional HTTP path diff --git a/x-pack/metricbeat/metricbeat.reference.yml b/x-pack/metricbeat/metricbeat.reference.yml index 15b3ed6132e..cc078f59c89 100644 --- a/x-pack/metricbeat/metricbeat.reference.yml +++ b/x-pack/metricbeat/metricbeat.reference.yml @@ -1822,7 +1822,7 @@ output.elasticsearch: # In case you modify this pattern you must update setup.template.name and setup.template.pattern accordingly. #index: "metricbeat-%{[agent.version]}-%{+yyyy.MM.dd}" - # Optional ingest node pipeline. By default no pipeline will be used. + # Optional ingest pipeline. By default no pipeline will be used. #pipeline: "" # Optional HTTP path diff --git a/x-pack/osquerybeat/osquerybeat.reference.yml b/x-pack/osquerybeat/osquerybeat.reference.yml index c84450660fc..990a7f85d7d 100644 --- a/x-pack/osquerybeat/osquerybeat.reference.yml +++ b/x-pack/osquerybeat/osquerybeat.reference.yml @@ -376,7 +376,7 @@ output.elasticsearch: # In case you modify this pattern you must update setup.template.name and setup.template.pattern accordingly. #index: "osquerybeat-%{[agent.version]}-%{+yyyy.MM.dd}" - # Optional ingest node pipeline. By default no pipeline will be used. + # Optional ingest pipeline. By default no pipeline will be used. #pipeline: "" # Optional HTTP path diff --git a/x-pack/packetbeat/packetbeat.reference.yml b/x-pack/packetbeat/packetbeat.reference.yml index 09dfd0e2e00..49b148eb80f 100644 --- a/x-pack/packetbeat/packetbeat.reference.yml +++ b/x-pack/packetbeat/packetbeat.reference.yml @@ -974,7 +974,7 @@ output.elasticsearch: # In case you modify this pattern you must update setup.template.name and setup.template.pattern accordingly. #index: "packetbeat-%{[agent.version]}-%{+yyyy.MM.dd}" - # Optional ingest node pipeline. By default no pipeline will be used. + # Optional ingest pipeline. By default no pipeline will be used. #pipeline: "" # Optional HTTP path diff --git a/x-pack/winlogbeat/winlogbeat.reference.yml b/x-pack/winlogbeat/winlogbeat.reference.yml index 565ccad26aa..58e93d2ded6 100644 --- a/x-pack/winlogbeat/winlogbeat.reference.yml +++ b/x-pack/winlogbeat/winlogbeat.reference.yml @@ -445,7 +445,7 @@ output.elasticsearch: # In case you modify this pattern you must update setup.template.name and setup.template.pattern accordingly. #index: "winlogbeat-%{[agent.version]}-%{+yyyy.MM.dd}" - # Optional ingest node pipeline. By default no pipeline will be used. + # Optional ingest pipeline. By default no pipeline will be used. #pipeline: "" # Optional HTTP path