Skip to content

[Custom Logs (Filestream)]: log.offset set to keyword vs long mapping #16760

@belimawr

Description

@belimawr

Integration Name

Custom Logs (Filestream) [filestream]

Dataset Name

No response

Integration Version

Any

Agent Version

Irrelevant

Agent Output Type

elasticsearch

Elasticsearch Version

Any

OS Version and Architecture

Irellevant

Software/API Version

No response

Error Message

No response

Event Original

No response

What did you do?

Installed the integration and started ingesting data

What did you see?

The Filestream Integration mappings set log.offset to keyword vs the other Integrations (where applicable) sets the field to long, causing mapping conflicts in the logs-* data view. Having the mapping issue here will cause issues down the line with dashboards, visualisations, etc.

What did you expect to see?

No mapping conflicts

Anything else?

Mapping examples from different integrations

Image Image Image Image

Metadata

Metadata

Assignees

Labels

Type

No fields configured for Bug.

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions