- Auditbeat Reference: other versions:
- Auditbeat overview
- Quick start: installation and configuration
- Set up and run
- Upgrade Auditbeat
- Configure
- Modules
- General settings
- Project paths
- Config file reloading
- Output
- Kerberos
- SSL
- Index lifecycle management (ILM)
- Elasticsearch index template
- Kibana endpoint
- Kibana dashboards
- Processors
- Define processors
- add_cloud_metadata
- add_cloudfoundry_metadata
- add_docker_metadata
- add_fields
- add_host_metadata
- add_id
- add_kubernetes_metadata
- add_labels
- add_locale
- add_network_direction
- add_nomad_metadata
- add_observer_metadata
- add_process_metadata
- add_session_metadata
- add_tags
- append
- community_id
- convert
- copy_fields
- decode_base64_field
- decode_duration
- decode_json_fields
- decode_xml
- decode_xml_wineventlog
- decompress_gzip_field
- detect_mime_type
- dissect
- dns
- drop_event
- drop_fields
- extract_array
- fingerprint
- include_fields
- move_fields
- rate_limit
- registered_domain
- rename
- replace
- syslog
- translate_ldap_attribute
- translate_sid
- truncate_fields
- urldecode
- Internal queue
- Logging
- HTTP endpoint
- Regular expression support
- Instrumentation
- Feature flags
- auditbeat.reference.yml
- How to guides
- Modules
- Exported fields
- Monitor
- Secure
- Troubleshoot
- Get Help
- Debug
- Understand logged metrics
- Common problems
- Auditbeat fails to watch folders because too many files are open
- Auditbeat uses too much bandwidth
- Error loading config file
- Found unexpected or unknown characters
- Logstash connection doesn’t work
- Publishing to Logstash fails with "connection reset by peer" message
- @metadata is missing in Logstash
- Not sure whether to use Logstash or Beats
- SSL client fails to connect to Logstash
- Monitoring UI shows fewer Beats than expected
- Dashboard could not locate the index-pattern
- High RSS memory usage due to MADV settings
- Contribute to Beats
Convert
editConvert
editThe convert
processor converts a field in the event to a different type, such
as converting a string to an integer.
The supported types include: integer
, long
, float
, double
, string
,
boolean
, and ip
.
The ip
type is effectively an alias for string
, but with an added validation
that the value is an IPv4 or IPv6 address.
processors: - convert: fields: - {from: "src_ip", to: "source.ip", type: "ip"} - {from: "src_port", to: "source.port", type: "integer"} ignore_missing: true fail_on_error: false
The convert
processor has the following configuration settings:
-
fields
-
(Required) This is the list of fields to convert. At least one item
must be contained in the list. Each item in the list must have a
from
key that specifies the source field. Theto
key is optional and specifies where to assign the converted value. Ifto
is omitted then thefrom
field is updated in-place. Thetype
key specifies the data type to convert the value to. Iftype
is omitted then the processor copies or renames the field without any type conversion. -
ignore_missing
-
(Optional) If
true
the processor continues to the next field when thefrom
key is not found in the event. If false then the processor returns an error and does not process the remaining fields. Default isfalse
. -
fail_on_error
-
(Optional) If false type conversion failures are ignored and
the processor continues to the next field. Default is
true
. -
tag
- (Optional) An identifier for this processor. Useful for debugging.
-
mode
-
(Optional) When both
from
andto
are defined for a field thenmode
controls whether tocopy
orrename
the field when the type conversion is successful. Default iscopy
.
ElasticON events are back!
Learn about the Elastic Search AI Platform from the experts at our live events.
Register nowWas this helpful?
Thank you for your feedback.