Here is the output -
{
"alerts" : {
"mappings" : {
"properties" : {
"@timestamp" : {
"type" : "date"
},
"agent" : {
"properties" : {
"hostname" : {
"type" : "keyword"
},
"name" : {
"type" : "keyword"
},
"version" : {
"type" : "keyword"
}
}
},
"alert_id" : {
"type" : "text",
"fields" : {
"keyword" : {
"type" : "keyword",
"ignore_above" : 256
}
}
},
"alert_instance_id" : {
"type" : "text",
"fields" : {
"keyword" : {
"type" : "keyword",
"ignore_above" : 256
}
}
},
"alert_name" : {
"type" : "text",
"fields" : {
"keyword" : {
"type" : "keyword",
"ignore_above" : 256
}
}
},
"beat" : {
"properties" : {
"hostname" : {
"type" : "keyword"
},
"name" : {
"type" : "keyword"
},
"version" : {
"type" : "keyword"
}
}
},
"ecs" : {
"properties" : {
"version" : {
"type" : "keyword"
}
}
},
"faied_count_alert" : {
"type" : "text",
"fields" : {
"keyword" : {
"type" : "keyword",
"ignore_above" : 256
}
}
},
"host" : {
"properties" : {
"architecture" : {
"type" : "keyword"
},
"containerized" : {
"type" : "boolean"
},
"geo" : {
"properties" : {
"city_name" : {
"type" : "keyword"
},
"continent_name" : {
"type" : "keyword"
},
"country_iso_code" : {
"type" : "keyword"
},
"country_name" : {
"type" : "keyword"
},
"location" : {
"type" : "geo_point"
},
"name" : {
"type" : "keyword"
},
"region_iso_code" : {
"type" : "keyword"
},
"region_name" : {
"type" : "keyword"
}
}
},
"hostname" : {
"type" : "keyword"
},
"id" : {
"type" : "keyword"
},
"ip" : {
"type" : "ip"
},
"mac" : {
"type" : "keyword"
},
"name" : {
"type" : "keyword"
},
"os" : {
"properties" : {
"build" : {
"type" : "keyword"
},
"codename" : {
"type" : "keyword"
},
"family" : {
"type" : "keyword"
},
"full" : {
"type" : "keyword"
},
"kernel" : {
"type" : "keyword"
},
"name" : {
"type" : "keyword"
},
"platform" : {
"type" : "keyword"
},
"version" : {
"type" : "keyword"
}
}
},
"type" : {
"type" : "keyword"
},
"user" : {
"properties" : {
"email" : {
"type" : "keyword"
},
"full_name" : {
"type" : "keyword"
},
"group" : {
"properties" : {
"id" : {
"type" : "keyword"
},
"name" : {
"type" : "keyword"
}
}
},
"hash" : {
"type" : "keyword"
},
"id" : {
"type" : "keyword"
},
"name" : {
"type" : "keyword"
}
}
}
}
},
"host_count" : {
"type" : "long"
},
"host_name" : {
"type" : "text",
"fields" : {
"keyword" : {
"type" : "keyword",
"ignore_above" : 256
}
}
},
"log" : {
"properties" : {
"file" : {
"properties" : {
"path" : {
"type" : "keyword"
}
}
},
"flags" : {
"type" : "keyword"
},
"level" : {
"type" : "keyword"
},
"offset" : {
"type" : "long"
},
"source" : {
"properties" : {
"address" : {
"type" : "keyword"
}
}
}
}
},
"message" : {
"type" : "text"
},
"severity" : {
"type" : "long"
},
"source_host" : {
"type" : "text",
"fields" : {
"keyword" : {
"type" : "keyword",
"ignore_above" : 256
}
}
},
"source_host_alert" : {
"type" : "text",
"fields" : {
"keyword" : {
"type" : "keyword",
"ignore_above" : 256
}
}
},
"source_ip" : {
"type" : "text",
"fields" : {
"keyword" : {
"type" : "keyword",
"ignore_above" : 256
}
}
},
"source_user" : {
"type" : "text",
"fields" : {
"keyword" : {
"type" : "keyword",
"ignore_above" : 256
}
}
},
"source_user_alert" : {
"type" : "text",
"fields" : {
"keyword" : {
"type" : "keyword",
"ignore_above" : 256
}
}
},
"total_count" : {
"type" : "long"
},
"triggered" : {
"type" : "date"
},
"user_name" : {
"type" : "text",
"fields" : {
"keyword" : {
"type" : "keyword",
"ignore_above" : 256
}
}
},
"watch_id" : {
"type" : "text",
"fields" : {
"keyword" : {
"type" : "keyword",
"ignore_above" : 256
}
}
}
}
}
}
}