The power of the pipeline definition is the ability for to be updated and created without a node restart (compared to Logstash). The definition is stored in a cluster state via the put pipeline API.
After having defined a pipeline, we need to provide it to the Elasticsearch cluster.
You need an up-and-running Elasticsearch installation, as we described in the Downloading and installing Elasticsearch recipe in Chapter 2, Downloading and Setup.
To execute curl
via the command line, you need to install curl
for your operative system.
To store or update an ingestion pipeline in Elasticsearch, we will perform the following steps:
We can store the ingest pipeline via a
PUT
call:curl -XPUT 'http://127.0.0.1:9200/_ingest/pipeline/add-user- john' -d '{ "description" : "Add user john field", "processors" : [ { "set" : { "field": "user", "value": "john...