You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Since packetbeat allows you to capture http headers and cookies, there's no way to control what some 3rd-party frameworks name their variables, and packetbeat should escape characters that will fail in ElasticSearch Mapping Parser.
expect packetbeat output to Elasticsearch to not break during ES bulk loading
The text was updated successfully, but these errors were encountered:
The problem with the header is that it contains fields like aaa.bbb with the dot notation which is not allowed under elasticsearch 2.x. I suggest we replaced . either with _ or -. Based on the naming standard we use in other fields _ would probably be the better option. @tsg Any thoughts here?
This issue has been automatically marked as stale because it has not had recent activity. It will be closed if no further activity occurs. Thank you for your contributions.
Reference discussion: https://discuss.elastic.co/t/mapper-parsing-exception-periods-in-field-name/51811/4
Since packetbeat allows you to capture http headers and cookies, there's no way to control what some 3rd-party frameworks name their variables, and packetbeat should escape characters that will fail in ElasticSearch Mapping Parser.
The text was updated successfully, but these errors were encountered: