New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Cloudflare Logpush integration does not support the correct available timestamp formats to match the output format options from the source #7762
Comments
Pinging @elastic/security-external-integrations (Team:Security-External Integrations) |
@travisestill Can you clarify please. The issue refers to logpush, but the linked code is in logpull. |
My apologies. I hadn't noticed that the link here (#5571 (comment)) was redirecting to the Logpull code. Here's the correct code: Lines 40 to 59 in 35f9966
And the Logpush docs suggest the same formats as the preferred: https://developers.cloudflare.com/logs/reference/log-output-options/
|
I've updated the original details to fix the previous references to logpull. The issue was reported against the Logpush integration, however, I think this may actually pertain to both Logpush and Logpull, because of the previously mentioned code compared to the options available. Both want to use |
Thanks. I have a fix for the logpull case. It can be applied to the logpush data streams too. |
Thanks @efd6 Just wanted to add that since |
The change handles that. We can't handle it natively since the |
Thanks, @efd6, for the quick turn around! I noticed the fixed version is 1.8.1, but the version in the EPR and corresponding pipelines is 1.4 (Elasticsearch version 8.6.2). Is the availability of the fix a way out from being available, or do the versions in the UI not reflect the release versioning? |
The latest version request 8.7.1.
|
Related GitHub issues and PR:
Issue: The @timestamp field for docs ingested from Logpush to Elasticsearch is pulled from
EdgeStartTimestamp
and the pipeline processor is defined to accept any of the following formats:integrations/packages/cloudflare_logpush/data_stream/http_request/elasticsearch/ingest_pipeline/default.yml
Lines 40 to 59 in 35f9966
However, per the Logpull documentation, the available formats that can be configured are as follows:
As a result, if the data comes through as UNIX for example (seconds from 1970) it would be interpreted as a UNIX_MS timestamp (milliseconds from 1970) resulting in a completely inaccurate timestamp.
Possible workarounds may include:
The text was updated successfully, but these errors were encountered: