Skip to content

AWS Integrations Mapping Error #1584

@phil-51

Description

@phil-51

I am ingesting Cloudtrail logs via Fleet and I'm getting errors stating the field has been stored as a Keyword.

If I check the Mappings in the Index Template I can't see a mapping for the event.created field, where if I check Azure (which I also have working), it does define event.created as a data.

As both Azure and AWS go in to the logs-* index pattern it causes a conflict.

This has been checked by an Elastic team member and confirmed that the field is missing at The field seems indeed to be missing: https://github.com/elastic/integrations/tree/master/packages/aws/data_stream/cloudtrail/fields

Issue initially raised on Elastic discuss forums:
https://discuss.elastic.co/t/aws-integrations-mapping-error/283502

Thanks

Metadata

Metadata

Assignees

Labels

Integration:awsAWSTeam:IntegrationsLabel for the Integrations teambugSomething isn't working, use only for issues

Type

No type
No fields configured for issues without a type.

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions