Hello everyone,
I have a stack with ELK and wazuh, I'm looking to change the type of some fields ("keyword" to "ip") to personal fields (srcip, dstip, etc.)
Their search fields in kibana are data.srcip, etc.
I tried this query in the dev tools:
PUT /wazuh-alerts-*/_mapping
{
"properties": {
"data" : {
"properties": {
"dstip": {
"type": "ip"
}
}
}
}
}
And I get this
{
"error" : {
"root_cause" : [
{
"type" : "illegal_argument_exception",
"reason" : "mapper [data.dstip] cannot be changed from type [keyword] to [ip]"
}
],
"type" : "illegal_argument_exception",
"reason" : "mapper [data.dstip] cannot be changed from type [keyword] to [ip]"
},
"status" : 400
}
Does anyone have a solution?
Thanks