Graylog2 / Graylog2/illuminate-documentation

Update Geo/AS field documentation to indicate deference to plugin

Open
#146 0 comments 0 reactions 0 assignees View on GitHub
triaged
Dominant language
HTML
Stars
2
Forks
0
PR merge metrics
No merged PRs in 30d

Description

Update the schema documentation for the `..._as_*` and `..._geo_*` fields to indicate they should not be extracted from messages when that data exists, that they should instead use the `vendor_` prefix to avoid field collisions.

Also provide clarity in the AS number field data type, considering the value may include the text prefix "AS".

Contributor guide

Open the contributing guide

Research direction

Start by locating the schema documentation entries for the `..._as_*` and `..._geo_*` fields. Review the AS number field's current data type and update the documentation so existing data defers to the plugin, extracted alternatives use the `vendor_` prefix, and values with the `AS` text prefix are clearly described.

Written by the indexing model from the issue text.

Assessment

Domain
documentation
Issue type
Documentation
Difficulty
2/5
Estimated time
1-3 hours
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
45/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.