Hi all,
I recently installed this add-one on my cluster (hfs, idxs, shs). I copied props.conf and transforms.conf into local directory and uncomment the mappings to sourcetype elastic:auditbeat:log. But this action had no effect and yet I just see one sourcetype: elastic:auditbeat:log
any ideas are appreciated.
Thanks.
What exactly did you change and what were the expected results?
The comments in transforms.conf and props.conf must not be un-commented because they are not valid settings.
Thank you. Yes I was wrong about transforms.conf
actually I wan to generate sourcetype from elastic:auditbeat:log based on events as This link has specified.