Open philippkahr opened 1 year ago
Pinging @elastic/ml-ui (:ml)
In this data set what type is event.original
?
Sticking to ECS: https://www.elastic.co/guide/en/ecs/current/ecs-event.html#field-event-original so not indexed and no doc_values. We can retrieve it from source though.
See as the description of the field is Raw text message of entire event
, I'm confused as to why it is a keyword
field and not text
I am not sure why the ECS docs, list it like this. Nonetheless, it is not indexed and not searchable, therefore the type should not matter at all.
Kibana version: 8.6.2
Describe the bug: It appears that you can only select
text
style fields. I would love to be able to select a field likeevent.original
since that contains the raw untreated source message. Also I should be able to select keywords.Steps to reproduce:
text
fields.Expected behavior: Empty list, should be returned with a message explaining why only xyz fields are usable.
Screenshots (if relevant):