Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
In ECS 8.2.0 multiple syslog fields (such as
log.syslog.version
andlog.syslog.structured_data
) have been introduced (elastic/ecs#1793).The current
SYSLOG5424BASE
pattern stores some of the syslog fileds in thesystem
field. This field is not defined in the ECS standard.This PR changes 2 fields of the SYSLOG5242BASE pattern, to use the newly defined fields of the ECS 8.2 definition.
system.syslog.version
->log.syslog.version
system.syslog.structured_data
->log.syslog.structured_data
The other fields of the
SYSLOG5242BASE
have been left unchanged, because changinghost.hostname
tolog.syslog.hostname
) would introduce a breaking change. I can image many pipelines rely on thehost.hostname
field.