The pages in this section build one worked example, OPNsense firewall syslog, in this order:
- Elastic Common Schema (ECS): pick standard field names before writing any mappings.
- Ingest pipelines: parse raw syslog lines into ECS fields.
- Index templates and data streams: define mappings and settings, and attach the pipeline.
- Validate mappings: test template and mapping JSON against a throwaway node before applying it anywhere real.