Hi!
We updated our logging system from Graylog2.4/ES2.x to Graylog3.2/ES5.6. According to the upgrade path no ES-reindexing was done neither should it be neccessary.
Unfortunately all the log fields show type ‘unknown’ now and if new data reaches a specific field its type shows ‘compound(string,unknown)’. New Fields with only ‘fresh’ data show the correct field type.
We recognized, that at least the ‘Show top values’ function does not work with ‘unknown’ fields.
Is there - beside reindexing - any known way to solve this problem? If not, do we have to expect further troubles with the ‘unknown’ fields?
Thanks in advance and Best Regards!