Skip to content

[filebeat][aws][vpcflow] mapping errors on logs with "NODATA" & "SKIPDATA" log_status #22716

@ynirk

Description

@ynirk

When testing filebeat 7.10.0 on AWS vpcflow, i noticed some parsing errors when aws.vpcflow.log_status is NODATA or SKIPDATA

With those status, the log line looks like the following:

version vpc-id subnet-id instance-id interface-id account-id - - - - - - - - - - start end - - SKIPDATA
version vpc-id subnet-id instance-id interface-id account-id - - - - - - - - - - start end - - NODATA

It generates mapping errors:

failed to parse field [aws.vpcflow.pkt_srcaddr] of type [ip] in document with id '229a9b7009-000001896666'. Preview of field's value: '-'

Metadata

Metadata

Assignees

Labels

FilebeatFilebeatTeam:PlatformsLabel for the Integrations - Platforms team

Type

No type
No fields configured for issues without a type.

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions