[Docs] Converting a Custom Implementation Update #1129
Closed
Description
The 'converting a custom implementation update' doc uses 'event.type: syslog' as an example, which isn't an allowed value.
We should use an allowed value in our example and take this page a step further by walking though mapping a sample log to both extended and core ECS fields.