elastic / elastic/integrations

elastic_agent.filebeat outputting url string field causing a conflict in Kibana

Open
#14,226 3 comments 0 reactions 0 assignees View on GitHub
Integration:elastic_agent needs:triage Team:Elastic-Agent Team:Elastic-Agent-Data-Plane
Dominant language
Handlebars
Stars
333
Forks
647
Avg merge
3d 4h
Merged PRs (30d)
209

Description

### Integration Name

Elastic Agent [elastic_agent]

### Dataset Name

elastic_agent.filebeat outputting url field causing a conflict in Kibana

### Integration Version

2.3.0

### Agent Version

8.17.6

### Agent Output Type

logstash

### Elasticsearch Version

8.17.6

### OS Version and Architecture

cloud

### Software/API Version

_No response_

### Error Message

Hi,

The elastic_agent integration is outputting a string field called url.

This is causing a conflict in Kibana with the ecs url object.

When we search url fields in Kibana, they don't show up in Available fields in Discover because of the conflict.

Please can you set the url in the correct ecs field?

I'm not sure which other elastic_agent integrations set the url field to a string.

Support ticket 01870899 has a sample event.

Thanks

### Event Original

_No response_

### What did you do?

Reviewed the elastic_agent.filebeat events. 189 events with the url keyword field in elastic_agent.filebeat in the last 30 days.

### What did you see?

Reviewed the elastic_agent.filebeat events. 189 events with the url keyword field in elastic_agent.filebeat in the last 30 days.

### What did you expect to see?

url in url.full or url.original.

### Anything else?

_No response_

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.