7.17 filebeat elasticsearch.slowlog
ingested log entry has full json log as message
#39935
Labels
Team:Monitoring
Stack Monitoring team
When using filebeat to ingest ES slowlogs, the resulting document does not have the correct message. Instead the message contains the full JSON log entry:
Reproduction:
7.17.21
for Elasticsearch and Filebeatelasticsearch.slowlog
module (For example by using the log+metrics feature in elastic cloud)Here an example of a log entry as it appears in the ES log file:
The text was updated successfully, but these errors were encountered: