Skip to main content

Supported Data Types

📘 Logs

Configuration

FieldTypeDefaultRequiredDescription
NameStringnonetrueUnique identifier within Sawmills.
AddressString${env:MY_POD_IP}trueThe address (IP or hostname) to receive Elasticsearch data.
PortInt9200trueThe port on which Elasticsearch data is received.

Advanced Options

FieldTypeDefaultRequiredDescription
Fallback EndpointStringnonefalseOptional fallback endpoint for Elasticsearch data reception. When the primary endpoint is unavailable, data will be routed to this fallback endpoint.
The pod’s IP address is retrieved by defining an environment variable MY_POD_IP from the pod’s status field status.podIP. You can access this value using ${env:MY_POD_IP} in your configuration to dynamically reference the pod’s IP at runtime.

Usage

The Elasticsearch source allows you to receive log data from Elasticsearch clusters. This source is specifically designed to handle log data ingestion and supports the standard Elasticsearch communication protocols & from Logstash.