'message' and 'port' field value is reflecting in the email. But url.host and http.connect.host value is missing. Only single fields like 'message' and 'port' values is getting in the email body.
Hi @jancodenew, thanks for reaching out! Can you let us know the type of rule you're using to create the alert as well as a sample of an alert that it generates? Thanks!
Above format is not fetching field values from my index. Looks like I have to change the template to match with ECS format.
Can we expect the same output for additional variable adding setup mentioned above in aggregation rules(Threshold rules)?
Also, kindly share if there is any workaround to manage this without changing templates to 100% ECS format. we have a huge number of index data that need to be changed to make these all adhere to ECS format.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.