Integration errors with netflow.log
data
#10254
Labels
bug
Something isn't working, use only for issues
Integration:netflow
NetFlow Records
Team:Security-Deployment and Devices
Deployment and Devices Security team [elastic/sec-deployment-and-devices]
Hi there --
I've been using the Netflow integration for some time now, but tonight I was poking around my instance and noticed that there were a massive number of errors on those logs, of the form:
array in field [source.ip] should only contain strings
Looking at the logs, it appears this is happening on all of the log messages, and further, it would seem that an IP of
1.2.3.4
is getting parsed (for all the fields) like:I confirmed I'm running the latest netflow integration (2.18.0), and looking at when this happened, it started (flipped a switch) on April 22. Not sure if that was the time of an integration update, or perhaps something that changed on the netflow sending side in our environment, I'm tracking that angle too, but wanted to point this out since everything else about the documents seems to look OK.
The text was updated successfully, but these errors were encountered: