...
${METRON_HOME}/bin/zk_load_configs.sh -m DUMP -z $ZOOKEEPER -c PARSER ENRICHMENT -n squid
This spits out configs to standard out. We provided a sensor name arg, so you should see one named "squid."
...
Re-ingest the data (see previous blog post for more detail)
cat /var/log/squid/access.log | ${HDP_HOME}/kafka-broker/bin/kafka-console-producer.sh --broker-list $BROKERLIST --topic squid
and the new messages should be automatically enriched. The Using the ES Head browser plugin, the new message should look as follows:
...