I’m using the latest stable Elasticsearch and Filebeat version 7.9.1 and enabled the cisco module to analyse the logs. I know there is an open issue about the module not showing the message fields on the logs UI (https://github.com/elastic/kibana/issues/72069 ).
But my question is about when creating the index pattern, usually if using Logstash with specific filters for cisco devices, I get around 150 fields on the pattern. But if using Cisco Module -> Filebeat -> Elasticsearch without Logstash I’m getting close to 4300 fields, this doesn’t seem right. (Everything else works as expected, dashboard, discover, etc.)
The most curious thing is that after stopping / starting the Filebeat service and deleting/recreating indexes and index patterns, SOMETIMES (without making any modifications to configuration files) I get close to 170 fields on the Filebeat index pattern. This I can’t replicate.
At the moment I’m back using Logstash.
If there is something I can provide like screenshots or configuration files let me know, or if this is a known issue can you point me to the right direction?