Closed frconil closed 12 months ago
We define text in https://github.com/elastic/integrations/blob/6e0b6ff1cb51e7b2b6b6b5021492da421d20c293/packages/elastic_agent/data_stream/endpoint_sercurity_logs/fields/fields.yml#L2 but ECS expects match_only_text .
text
match_only_text
Similarly event.dataset (https://github.com/elastic/integrations/blob/6e0b6ff1cb51e7b2b6b6b5021492da421d20c293/packages/elastic_agent/data_stream/endpoint_sercurity_logs/fields/base-fields.yml#L13) is set as constant_keyword when the data quality dashboard expect keyword.
event.dataset
constant_keyword
keyword
.ds-logs-elastic_agent.endpoint_security`
same family
Pinging @elastic/elastic-agent (Team:Elastic-Agent)
We define
text
in https://github.com/elastic/integrations/blob/6e0b6ff1cb51e7b2b6b6b5021492da421d20c293/packages/elastic_agent/data_stream/endpoint_sercurity_logs/fields/fields.yml#L2 but ECS expectsmatch_only_text
.Similarly
event.dataset
(https://github.com/elastic/integrations/blob/6e0b6ff1cb51e7b2b6b6b5021492da421d20c293/packages/elastic_agent/data_stream/endpoint_sercurity_logs/fields/base-fields.yml#L13) is set asconstant_keyword
when the data quality dashboard expectkeyword
..ds-logs-elastic_agent.endpoint_security`
keyword
constant_keyword
same family
match_only_text
text
same family