- Journalbeat Reference for 6.5-7.15:
- Overview
- Getting started with Journalbeat
- Setting up and running Journalbeat
- Configuring Journalbeat
- Configure inputs
- Specify general settings
- Configure the internal queue
- Configure the output
- Configure index lifecycle management
- Specify SSL settings
- Filter and enhance the exported data
- Define processors
- Add cloud metadata
- Add fields
- Add labels
- Add the local time zone
- Add tags
- Decode CSV fields
- Decode JSON fields
- Community ID Network Flow Hash
- Convert
- Drop events
- Drop fields from events
- Keep fields from events
- Rename fields from events
- Add Kubernetes metadata
- Add Docker metadata
- Add Host metadata
- Add Observer metadata
- Dissect strings
- DNS Reverse Lookup
- Add process metadata
- Script Processor
- Extract array
- Parse data by using ingest node
- Enrich events with geoIP information
- Configure project paths
- Configure the Kibana endpoint
- Load the Elasticsearch index template
- Configure logging
- Use environment variables in the configuration
- YAML tips and gotchas
- Regular expression support
- HTTP Endpoint
- journalbeat.reference.yml
- Exported fields
- Monitoring Journalbeat
- Securing Journalbeat
- Troubleshooting
This functionality is experimental and may be changed or removed completely in a
future release. Elastic will take a best effort approach to fix any issues, but
experimental features are not subject to the support SLA of official GA
features.
Extract array
editExtract array
editThis functionality is in technical preview and may be changed or removed in a future release. Elastic will work to fix any issues, but features in technical preview are not subject to the support SLA of official GA features.
The extract_array
processor populates fields with values read from an array
field. The following example will populate source.ip
with the first element of
the my_array
field, destination.ip
with the second element, and
network.transport
with the third.
processors: - extract_array: field: my_array mappings: source.ip: 0 destination.ip: 1 network.transport: 2
The following settings are supported:
-
field
- The array field whose elements are to be extracted.
-
mappings
- Maps each field name to an array index. Use 0 for the first element in the array. Multiple fields can be mapped to the same array element.
-
ignore_missing
-
(Optional) Whether to ignore events where the array field is
missing. The default is
false
, which will fail processing of an event if the specified field does not exist. Set it totrue
to ignore this condition. -
overwrite_keys
-
Whether the target fields specified in the mapping are
overwritten if they already exist. The default is
false
, which will fail processing if a target field already exists. -
fail_on_error
-
(Optional) If set to
true
and an error happens, changes to the event are reverted, and the original event is returned. If set tofalse
, processing continues despite errors. Default istrue
. -
omit_empty
-
(Optional) Whether empty values are extracted from the array. If
set to
true
, instead of the target field being set to an empty value, it is left unset. The empty string (""
), an empty array ([]
) or an empty object ({}
) are considered empty values. Default isfalse
.
Was this helpful?
Thank you for your feedback.