You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
The elastic ingest pipelines from the integration m365_defender fails, when I get the data over logstash.
Works: Elastic-Agent with m365_defender integration, Output Elasticsearch Doesn't work: Elastic-Agent with m365_defender integration, Output Logstash. The ingest pipeline stops working with this error.message: field [event.original] already exists
Reason: Logstash adds the field event.original which is already similar to the field message after processing with logstash.
Problem in pipeline logs-m365_defender.incident-2.2.0 :
The elastic ingest pipelines from the integration m365_defender fails, when I get the data over logstash.
Works: Elastic-Agent with m365_defender integration, Output Elasticsearch
Doesn't work: Elastic-Agent with m365_defender integration, Output Logstash. The ingest pipeline stops working with this error.message:
field [event.original] already exists
Reason: Logstash adds the field event.original which is already similar to the field message after processing with logstash.
Problem in pipeline logs-m365_defender.incident-2.2.0 :
Possible fix:
The problem could also exist in so some other pipeleline. Please check as well
The text was updated successfully, but these errors were encountered: