Packetbeat only populates a small set of fields in the OS packetbeat index.
Data is coming in and a smaller set of fields populate - but lots of fields are missing and never populated although the config. looks ok.
As an example the network.protocol field is missing from the index but the network.transport and network.packets fields gets populated.
My config is: packetbeat —> logstash (without any filters) —> Opensearch 2.2
(The only packetbeat type that gets populated are of type flow.)
Do anyone see something odd/strange in my config. below that needs to be fixed?
- type: dns
- type: http
ports: [80, 8000, 8080, 9200]
- type: mysql
- type: redis
- type: pgsql
- type: tls
ports: [443, 993, 995, 5223, 8443, 8883, 9243]
Would really appreciate if someone knows how it is possible to resolve this