elastic / beats

:tropical_fish: Beats - Lightweight shippers for Elasticsearch & Logstash
https://www.elastic.co/products/beats
Other
103 stars 4.92k forks source link

[FIlebeat] Azure Signin data => field [message] already exists #27240

Open willemdh opened 3 years ago

willemdh commented 3 years ago

Issue in https://github.com/elastic/beats/blob/11b545a182909de2234aed8bf2916f16f2234f5e/x-pack/filebeat/module/azure/signinlogs/ingest/pipeline.yml#L238

I cannot provide any sample logs for now. Maybe later @legoguy1000

legoguy1000 commented 3 years ago

I won't be able to do much without the sample events that cause the issue as I will not be able to validate the changes fix the issue.

elasticmachine commented 3 years ago

Pinging @elastic/security-external-integrations (Team:Security-External Integrations)

elasticmachine commented 3 years ago

Pinging @elastic/integrations (Team:Integrations)

botelastic[bot] commented 2 years ago

Hi! We just realized that we haven't looked into this issue in a while. We're sorry!

We're labeling this issue as Stale to make it hit our filters and make sure we get back to it as soon as possible. In the meantime, it'd be extremely helpful if you could take a look at it as well and confirm its relevance. A simple comment with a nice emoji will be enough :+1. Thank you for your contribution!

nemhods commented 1 year ago

Hello, encountering this too and I can provide sample data. This is a raw JSON from the event hub, heavily redacted of course.

m365-error-message.json

elasticmachine commented 9 months ago

Pinging @elastic/security-service-integrations (Team:Security-Service Integrations)