Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[journald] ECS conflicts with host.ip and source.ip fields #9690

Open
Tracked by #37086
nemhods opened this issue Apr 23, 2024 · 3 comments
Open
Tracked by #37086

[journald] ECS conflicts with host.ip and source.ip fields #9690

nemhods opened this issue Apr 23, 2024 · 3 comments
Labels
Integration:journald Custom Journald logs Team:Elastic-Agent-Data-Plane Label for the Agent Data Plane team [elastic/elastic-agent-data-plane]

Comments

@nemhods
Copy link

nemhods commented Apr 23, 2024

Hey,

after installing the Journald integration in my 8.12.1 Kibana / Fleet, I saw mapping conflicts in the logs-* Data View. The data quality dashboard shows these issues as well:
image

Journald integration uses the logs-logs dataset, and it seems to lack mappings for the fields source.ip and host.ip in the package component template.

Indeed, https://github.com/elastic/integrations/blob/main/packages/journald/fields/ecs.yml seems to be missing the references to source.ip / host.ip. I'm not sure if this is the correct place to add them though.

@jamiehynds jamiehynds added the Team:Elastic-Agent-Data-Plane Label for the Agent Data Plane team [elastic/elastic-agent-data-plane] label Apr 24, 2024
@elasticmachine
Copy link

Pinging @elastic/elastic-agent-data-plane (Team:Elastic-Agent-Data-Plane)

@jamiehynds jamiehynds added the Integration:journald Custom Journald logs label Apr 24, 2024
@pierrehilbert
Copy link
Contributor

@belimawr it looks like a good candidate to add to elastic/beats#37086

@belimawr
Copy link
Contributor

@belimawr it looks like a good candidate to add to elastic/beats#37086

Inded it is, I'll add it to the list of tasks there.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Integration:journald Custom Journald logs Team:Elastic-Agent-Data-Plane Label for the Agent Data Plane team [elastic/elastic-agent-data-plane]
Projects
None yet
Development

No branches or pull requests

5 participants