[Cisco FTD] Pipeline Error for Event 113019 #9198
Labels
bug
Something isn't working
Integration:CiscoFTD
Cisco FTD Firepower Threat Defense
Team:Security-Deployment and Devices
Deployment and Devices Security team
The Cisco FTD integration raises a pipeline error on events with Message ID 113019.
The code that errors is line 1648 here:
https://github.com/elastic/integrations/blob/fc99cc8fcbe193be818f03f26fc3ef9a3d341562/packages/cisco_ftd/data_stream/log/elasticsearch/ingest_pipeline/default.yml#L1646C1-L1649C100
The error message is
cannot access method/field [bytes] from a null def reference
and seems to be caused by a script trying to add a value to the network.bytes field (ctx.network.bytes) when the network parent field doesn't exist.
A document that can raise the error is below.
The text was updated successfully, but these errors were encountered: