As a user performing troubleshooting, I would like to be able to correlate the stream ID from the agent policy with both the logs and metrics. IIRC from the last time I was trying to do this in Kibana, there were a few different fields that held this ID value and not all of them were indexed.
I think it would be helpful for Elastic Agent to give guidance on logging schema for its constituent inputs to follow. With that written down somewhere we could then make changes to ensure that it is followed and make sure those fields are mapped consistently in the elastic_agent integration. Here's a quick idea building upon on the component fields I see in the elastic_agent logs.
Field
Description
Examples
component.kind
Kind of component. These are general high-level concepts.
input, processor, output
component.type
Type of component. Type specifies a named implementation of the specific component kind.
The component.x labels coming from the raw Beat logs would take precedence over any component.x labels being added by Elastic Agent as the logs flows through it.
Originally suggested by @andrewkroh in https://github.com/elastic/elastic-agent/issues/3640#issuecomment-1781875889
As a user performing troubleshooting, I would like to be able to correlate the stream ID from the agent policy with both the logs and metrics. IIRC from the last time I was trying to do this in Kibana, there were a few different fields that held this ID value and not all of them were indexed.
I think it would be helpful for Elastic Agent to give guidance on logging schema for its constituent inputs to follow. With that written down somewhere we could then make changes to ensure that it is followed and make sure those fields are mapped consistently in the elastic_agent integration. Here's a quick idea building upon on the component fields I see in the elastic_agent logs.
Example of data from beats:
The
component.x
labels coming from the raw Beat logs would take precedence over anycomponent.x
labels being added by Elastic Agent as the logs flows through it.