The elastic_agent integration is setting dynamic: false on all data streams, but indexes additional fields. These additional fields are shown in Discover, but as they are not mapped it's not possible to search on them.
The most notable one is service.name (see Slack thread.
Ideally, dynamic: false should be removed so all fields are mapped properly. Alternatively, service.name is added explicitly to all data streams that set it.
The elastic_agent integration is setting
dynamic: false
on all data streams, but indexes additional fields. These additional fields are shown in Discover, but as they are not mapped it's not possible to search on them.The most notable one is
service.name
(see Slack thread.Ideally,
dynamic: false
should be removed so all fields are mapped properly. Alternatively,service.name
is added explicitly to all data streams that set it.