philhagen / sof-elk

Configuration files for the SOF-ELK VM
GNU General Public License v3.0
1.46k stars 272 forks source link

GCP Logs Missing source_geo.location Field #249

Closed joshlemon closed 2 years ago

joshlemon commented 2 years ago

The gcp-* index doesn’t have source_geo.location field, however, it contains all the geo fields when parsed with Maxmind API enabled.

It should be setup the same way as the azure-* index which does include the source_geo.location field.

This is needed to be able to create a Geo Map in a dashboard.

philhagen commented 2 years ago

@joshlemon this should be g2g in develop. clear the gcp index before running sudo sof-elk_update.sh