-
Notifications
You must be signed in to change notification settings - Fork 4.9k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[Filebeat] mapper [o365.audit.Folders.FolderItems.SizeInBytes] cannot be changed from type [long] to [float] #36155
Labels
Comments
kowalczyk-p
changed the title
mapper [o365.audit.Folders.FolderItems.SizeInBytes] cannot be changed from type [long] to [float]
[Filebeat] mapper [o365.audit.Folders.FolderItems.SizeInBytes] cannot be changed from type [long] to [float]
Jul 25, 2023
botelastic
bot
added
the
needs_team
Indicates that the issue/PR needs a Team:* label
label
Jul 25, 2023
Pinging @elastic/security-external-integrations (Team:Security-External Integrations) |
botelastic
bot
removed
the
needs_team
Indicates that the issue/PR needs a Team:* label
label
Aug 11, 2023
@kowalczyk-p Are you able to provide the mapping for the affected index, and an example document that fails from the logstash logs? |
Example document (redacted):
Index mapping is pretty big so I'm adding it as attachment. |
norrietaylor
added
Team:Security-Service Integrations
Security Service Integrations Team
and removed
Team:Security-External Integrations
labels
Jan 31, 2024
Pinging @elastic/security-service-integrations (Team:Security-Service Integrations) |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Labels
Please post all questions and issues on https://discuss.elastic.co/c/beats
before opening a Github Issue. Your questions will reach a wider audience there,
and if we confirm that there is a bug, then you can open a new issue.
For security vulnerabilities please only send reports to [email protected].
See https://www.elastic.co/community/security for more information.
Please include configurations and logs if available.
For confirmed bugs, please report:
In my setup Filebeat fetches o365 logs and sends them to Elasticsearch via Logstash. Index template was exported from Filebeat and set up in Elasticsearch. In logstash logs I see errors "Could not index event to Elasticsearch" with reason
Field o365.audit.Folders.FolderItems.SizeInBytes is not defined in index template from Filebeat. Version is 8.6.2.
The text was updated successfully, but these errors were encountered: