elastic / elastic/integrations

[Windows]: process.command_line - field malformed

Open
#20,107 2 comments 0 reactions 0 assignees View on GitHub
Integration:windows needs:triage Team:Elastic-Agent-Data-Plane
Dominant language
Handlebars
Stars
333
Forks
647
Avg merge
2d 18h
Merged PRs (30d)
182

Description

### Integration Name

Windows [packages/windows]

### Dataset Name

Windows Powershell logs

### Integration Version

3.8.3

### Agent Version

9.4.3

### Agent Output Type

elasticsearch

### Elasticsearch Version

9.4.3

### OS Version and Architecture

Windows Server 2022 Standard

### Software/API Version

_No response_

### Error Message

Image
Field malformed.

### Event Original

_No response_

### What did you do?

Integrated Windows Server and collect powershell log data via Windows Integration.

### What did you see?

Our Data Set Quality from the windows powershell logs are degraded caused by the field "process.command_line".
Potential cause; Field malformed.

### What did you expect to see?

Proper parsing

### Anything else?

_No response_

Contributor guide

Open the contributing guide

Research direction

Start in packages/windows and inspect how Windows PowerShell logs populate and map process.command_line for Elasticsearch output. Reproduce the malformed field with the reported Windows Server 2022 setup and identify the relevant parsing or mapping behavior; done means the field is properly parsed without degrading dataset quality.

Written by the indexing model from the issue text.

Assessment

Tech stack
elasticsearch, handlebars, powershell
Domain
observability-sre, operating-systems
Issue type
Bug
Difficulty
3/5
Estimated time
1-2 days
Activity status
Quiet
Clarity
Needs clarification
Newbie friendliness
45/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.