{
"_doc": {
"dynamic_templates": [],
"properties": {
"okta": {
"type": "object",
"properties": {
"debug_context": {
"type": "object",
"properties": {
"debug_data": {
"type": "object",
"properties": {
"suspicious_activity_event_type": {
"ignore_above": 1024,
"type": "keyword"
},
"suspicious_activity_event_state": {
"ignore_above": 1024,
"type": "keyword"
},
"suspicious_activity_event_longitude": {
"type": "float"
},
"suspicious_activity_event_ip": {
"type": "ip"
},
"suspicious_activity_event_latitude": {
"type": "float"
},
"suspicious_activity_event_city": {
"ignore_above": 1024,
"type": "keyword"
},
"suspicious_activity_browser": {
"ignore_above": 1024,
"type": "keyword"
},
"suspicious_activity_event_transaction_id": {
"ignore_above": 1024,
"type": "keyword"
},
"suspicious_activity_event_id": {
"ignore_above": 1024,
"type": "keyword"
},
"suspicious_activity_os": {
"ignore_above": 1024,
"type": "keyword"
},
"suspicious_activity_event_country": {
"ignore_above": 1024,
"type": "keyword"
},
"suspicious_activity_timestamp": {
"type": "date"
}
}
}
}
}
}
}
}
}
}
The following processors need to be added to the ingest pipeline prior to json being dropped:
{
"rename": {
"ignore_failure": true,
"field": "json.debugContext.debugData.suspiciousActivityBrowser",
"target_field": "okta.debug_context.debug_data.suspicious_activity_browser",
"ignore_missing": true
}
},
{
"rename": {
"ignore_failure": true,
"field": "json.debugContext.debugData.suspiciousActivityEventCity",
"target_field": "okta.debug_context.debug_data.suspicious_activity_event_city",
"ignore_missing": true
}
},
{
"rename": {
"ignore_failure": true,
"field": "json.debugContext.debugData.suspiciousActivityEventCountry",
"target_field": "okta.debug_context.debug_data.suspicious_activity_event_country",
"ignore_missing": true
}
},
{
"rename": {
"ignore_failure": true,
"field": "json.debugContext.debugData.suspiciousActivityEventId",
"target_field": "okta.debug_context.debug_data.suspicious_activity_event_id",
"ignore_missing": true
}
},
{
"rename": {
"ignore_failure": true,
"field": "json.debugContext.debugData.suspiciousActivityEventIp",
"target_field": "okta.debug_context.debug_data.suspicious_activity_event_ip",
"ignore_missing": true
}
},
{
"rename": {
"ignore_failure": true,
"field": "json.debugContext.debugData.suspiciousActivityEventLatitude",
"target_field": "okta.debug_context.debug_data.suspicious_activity_event_latitude",
"ignore_missing": true
}
},
{
"rename": {
"ignore_failure": true,
"field": "json.debugContext.debugData.suspiciousActivityEventLongitude",
"target_field": "okta.debug_context.debug_data.suspicious_activity_event_longitude",
"ignore_missing": true
}
},
{
"rename": {
"ignore_failure": true,
"field": "json.debugContext.debugData.suspiciousActivityEventState",
"target_field": "okta.debug_context.debug_data.suspicious_activity_event_state",
"ignore_missing": true
}
},
{
"rename": {
"ignore_failure": true,
"field": "json.debugContext.debugData.suspiciousActivityEventTransactionId",
"target_field": "okta.debug_context.debug_data.suspicious_activity_event_transaction_id",
"ignore_missing": true
}
},
{
"rename": {
"ignore_failure": true,
"field": "json.debugContext.debugData.suspiciousActivityEventType",
"target_field": "okta.debug_context.debug_data.suspicious_activity_event_type",
"ignore_missing": true
}
},
{
"rename": {
"ignore_failure": true,
"field": "json.debugContext.debugData.suspiciousActivityOs",
"target_field": "okta.debug_context.debug_data.suspicious_activity_os",
"ignore_missing": true
}
},
{
"rename": {
"ignore_failure": true,
"field": "json.debugContext.debugData.suspiciousActivityTimestamp",
"target_field": "okta.debug_context.debug_data.suspicious_activity_timestamp",
"ignore_missing": true
}
},
The following needs to be added to the Filebeat mapping:
The following processors need to be added to the ingest pipeline prior to json being dropped:
For confirmed bugs, please report: