Hey jochen, I can’t send the whole lot due to the character limit, so this is the current index minus a bunch of the winlogbeat fields but the ‘source’ field is covered which is the primary culprit.
graylog_18" : {
"mappings" : {
"message" : {
"dynamic_templates" : [
{
"internal_fields" : {
"match" : "gl2_*",
"mapping" : {
"type" : "keyword"
}
}
},
{
"store_generic" : {
"match" : "*",
"mapping" : {
"index" : "not_analyzed"
}
}
}
],
"properties" : {
"Action" : {
"type" : "keyword"
},
"Alliance_Data_Bit9EndpointVisibility" : {
"type" : "keyword"
},
"Alliance_Link_Bit9EndpointVisibility" : {
"type" : "keyword"
},
"Alliance_Score_Bit9EndpointVisibility" : {
"type" : "keyword"
},
"Alliance_Updated_Bit9EndpointVisibility" : {
"type" : "date"
},
"BASE10NUM" : {
"type" : "keyword"
},
"Client_IP" : {
"type" : "keyword"
},
"Client_Username" : {
"type" : "keyword"
},
"Comms_IP" : {
"type" : "keyword"
},
"Company_Name" : {
"type" : "keyword"
},
"DATE" : {
"type" : "keyword"
},
"DATE_EU" : {
"type" : "keyword"
},
"Description" : {
"type" : "keyword"
},
"DestIP" : {
"type" : "keyword"
},
"DestPort" : {
"type" : "keyword"
},
"EvtLevel" : {
"type" : "keyword"
},
"FPAction" : {
"type" : "keyword"
},
"FPBytes_In" : {
"type" : "keyword"
},
"FPBytes_In_Num" : {
"type" : "long"
},
"FPBytes_Out" : {
"type" : "keyword"
},
"FPBytes_Out_Num" : {
"type" : "long"
},
"FPCategory" : {
"type" : "keyword"
},
"FPDisposition" : {
"type" : "keyword"
},
"FPDst_Host" : {
"type" : "keyword"
},
"FPDst_IP" : {
"type" : "keyword"
},
"FPDst_Port" : {
"type" : "keyword"
},
"FPDuration" : {
"type" : "keyword"
},
"FPDuration_Numb" : {
"type" : "long"
},
"FPHTTP_Content_Type" : {
"type" : "keyword"
},
"FPHTTP_Method" : {
"type" : "keyword"
},
"FPHTTP_Proxy_Status_Code" : {
"type" : "keyword"
},
"FPHTTP_Response" : {
"type" : "keyword"
},
"FPHostIP" : {
"type" : "keyword"
},
"FPLDAP_Connection" : {
"type" : "keyword"
},
"FPPolicy" : {
"type" : "keyword"
},
"FPReason" : {
"type" : "keyword"
},
"FPRole" : {
"type" : "keyword"
},
"FPSeverity" : {
"type" : "keyword"
},
"FPSrc_Host" : {
"type" : "keyword"
},
"FPSrc_Port" : {
"type" : "keyword"
},
"FPURL" : {
"type" : "keyword"
},
"FPUser" : {
"type" : "keyword"
},
"FPUser_Agent" : {
"type" : "keyword"
},
"FPUser_OU" : {
"type" : "keyword"
},
"FPVersion" : {
"type" : "keyword"
},
"FWDate" : {
"type" : "date"
},
"FWTime" : {
"type" : "keyword"
},
"File_Version" : {
"type" : "keyword"
},
"First_Seen" : {
"type" : "date"
},
"Group" : {
"type" : "keyword"
},
"HOSTNAME" : {
"type" : "keyword"
},
"HOUR" : {
"type" : "keyword"
},
"HTTP_Status" : {
"type" : "keyword"
},
"Host" : {
"type" : "keyword"
},
"Hostname" : {
"type" : "keyword"
},
"ID" : {
"type" : "keyword"
},
"IPV4" : {
"type" : "keyword"
},
"ISO8601_TIMEZONE" : {
"type" : "keyword"
},
"Interface_IP" : {
"type" : "keyword"
},
"Last_Update" : {
"type" : "date"
},
"MINUTE" : {
"type" : "keyword"
},
"MONTHDAY" : {
"type" : "keyword"
},
"MONTHNUM" : {
"type" : "keyword"
},
"Method" : {
"type" : "keyword"
},
"PROTOCOL" : {
"type" : "keyword"
},
"Port" : {
"type" : "keyword"
},
"Process_Guid" : {
"type" : "keyword"
},
"Process_MD5" : {
"type" : "keyword"
},
"Process_Name" : {
"type" : "keyword"
},
"Process_Path" : {
"type" : "keyword"
},
"Product" : {
"type" : "keyword"
},
"Product_Name" : {
"type" : "keyword"
},
"Product_Version" : {
"type" : "keyword"
},
"Protocol_Substatus" : {
"type" : "keyword"
},
"Reason" : {
"type" : "keyword"
},
"Referrer" : {
"type" : "keyword"
},
"Result" : {
"type" : "keyword"
},
"SECOND" : {
"type" : "keyword"
},
"SEP_event_action" : {
"type" : "keyword"
},
"SEP_event_app" : {
"type" : "keyword"
},
"SEP_event_begin" : {
"type" : "keyword"
},
"SEP_event_category" : {
"type" : "keyword"
},
"SEP_event_category_code" : {
"type" : "keyword"
},
"SEP_event_description" : {
"type" : "keyword"
},
"SEP_event_direction" : {
"type" : "keyword"
},
"SEP_event_domain" : {
"type" : "keyword"
},
"SEP_event_end" : {
"type" : "keyword"
},
"SEP_event_localhost_id" : {
"type" : "keyword"
},
"SEP_event_localhost_ip" : {
"type" : "keyword"
},
"SEP_event_localhost_port" : {
"type" : "keyword"
},
"SEP_event_location" : {
"type" : "keyword"
},
"SEP_event_message" : {
"type" : "keyword"
},
"SEP_event_protocol" : {
"type" : "keyword"
},
"SEP_event_quantity" : {
"type" : "keyword"
},
"SEP_event_remote_hostname" : {
"type" : "keyword"
},
"SEP_event_remote_id" : {
"type" : "keyword"
},
"SEP_event_remote_ip" : {
"type" : "keyword"
},
"SEP_event_remote_port" : {
"type" : "keyword"
},
"SEP_event_remotefilepath" : {
"type" : "keyword"
},
"SEP_event_rule" : {
"type" : "keyword"
},
"SEP_event_server" : {
"type" : "keyword"
},
"SEP_event_source" : {
"type" : "keyword"
},
"SEP_event_user" : {
"type" : "keyword"
},
"Search_Terms_v1" : {
"type" : "keyword"
},
"Segment_ID" : {
"type" : "keyword"
},
"Sensor_ID" : {
"type" : "keyword"
},
"Server_IP" : {
"type" : "keyword"
},
"Signed" : {
"type" : "keyword"
},
"Size" : {
"type" : "keyword"
},
"SrcIP" : {
"type" : "keyword"
},
"SrcPort" : {
"type" : "keyword"
},
"Start_Time" : {
"type" : "date"
},
"SyslogPriority" : {
"type" : "keyword"
},
"SyslogSeverity" : {
"type" : "keyword"
},
"TIME" : {
"type" : "keyword"
},
"TIMESTAMP_ISO8601" : {
"type" : "date"
},
"Time_Taken" : {
"type" : "keyword"
},
"Time_Taken_Numb" : {
"type" : "long"
},
"Timestamp" : {
"type" : "keyword"
},
"Type" : {
"type" : "keyword"
},
"URI" : {
"type" : "keyword"
},
"URI_Query" : {
"type" : "keyword"
},
"User" : {
"type" : "keyword"
},
"User_Agent" : {
"type" : "keyword"
},
"Vendor" : {
"type" : "keyword"
},
"WatchlistID" : {
"type" : "keyword"
},
"Watchlist_ID" : {
"type" : "keyword"
},
"Watchlist_Name" : {
"type" : "keyword"
},
"Windows_Status" : {
"type" : "keyword"
},
"YEAR" : {
"type" : "keyword"
},
"collector_node_id" : {
"type" : "keyword"
},
"connection_id" : {
"type" : "long"
},
"connection_requests" : {
"type" : "long"
},
"facility" : {
"type" : "keyword"
},
"file" : {
"type" : "keyword"
},
"from_gelf" : {
"type" : "keyword"
},
"from_syslog" : {
"type" : "keyword"
},
"full_message" : {
"type" : "text",
"analyzer" : "standard"
},
"gl2_remote_ip" : {
"type" : "keyword"
},
"gl2_remote_port" : {
"type" : "keyword"
},
"gl2_source_collector" : {
"type" : "keyword"
},
"gl2_source_input" : {
"type" : "keyword"
},
"gl2_source_node" : {
"type" : "keyword"
},
"http_referer" : {
"type" : "keyword"
},
"http_user_agent" : {
"type" : "keyword"
},
"http_version" : {
"type" : "keyword"
},
"icmpcode" : {
"type" : "keyword"
},
"icmptype" : {
"type" : "keyword"
},
"info" : {
"type" : "keyword"
},
"input_type" : {
"type" : "keyword"
},
"level" : {
"type" : "long"
},
"message" : {
"type" : "text",
"analyzer" : "standard"
},
"millis" : {
"type" : "float"
},
"name" : {
"type" : "keyword"
},
"offset" : {
"type" : "long"
},
"path" : {
"type" : "keyword"
},
"remote_addr" : {
"type" : "keyword"
},
"remote_user" : {
"type" : "keyword"
},
"request_path" : {
"type" : "keyword"
},
"request_verb" : {
"type" : "keyword"
},
"response_bytes" : {
"type" : "long"
},
"response_status" : {
"type" : "long"
},
"source" : {
"type" : "text",
"analyzer" : "analyzer_keyword",
"fielddata" : true
},
"streams" : {
"type" : "keyword"
},
"tags" : {
"type" : "keyword"
},
"tcpack" : {
"type" : "keyword"
},
"tcpflags" : {
"type" : "keyword"
},
"tcpsyn" : {
"type" : "keyword"
},
"tcpwin" : {
"type" : "keyword"
},
"timestamp" : {
"type" : "date",
"format" : "yyyy-MM-dd HH:mm:ss.SSS"
},
"type" : {
"type" : "keyword"
},
"winlogbeat_activity_id" : {
"type" : "keyword"
},
"winlogbeat_computer_name" : {
"type" : "keyword"
},
"winlogbeat_event_data_AccessList" : {
"type" : "keyword"
},
"winlogbeat_event_data_AccessMask" : {
"type" : "keyword"
},
"winlogbeat_event_data_ProcessID" : {
"type" : "keyword"
},
},
"winlogbeat_version" : {
"type" : "long"
}
}
}
}
},
Thanks in advance.