Skip to content

Avoid existing data (if present) in the received json event from being overwritten by added ECS metadata. #164

Description

@kxs-who

According to the documentation (https://www.elastic.co/guide/en/logstash/current/plugins-inputs-http.html#plugins-inputs-http-ecs_metadata), the following ECS metadata is populated by the http input plugin:

  • Host IP address
  • Complete HTTP headers
  • HTTP version
  • client user agent
  • host domain and port
  • HTTP method
  • Query path
  • Request content length
  • Request mime type

The following issue was logged because the host field was being overwritten: #61
We would like the http input plugin to have a way to prevent overwriting not just the host metadata but all metadata.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions