Well,
That did not clear it up and I am still getting the same error today. Here is the full sanitized event. Maybe you can find a duplicate field that I didn't?
[
2021-08-12T00: 04: 18,
688
][WARN
][logstash.outputs.elasticsearch
] Could not index event to Elasticsearch. {
:status=>400,
:action=>[
"index",
{
:_id=>nil,
:_index=>"so-beats",
:routing=>nil,
:pipeline=>"beats.common"
},
{
"related"=>{
"hash"=>[
"118729dd62b9422d21afe5cebd564f8a",
"b76ce2bba63bd2949fa6e36fba963379b9d682f7642cd3782d9818fcd30a3e00",
"d2466cd4c38ecef8aab0ee78b79fc8b8"
],
"user"=>"NETWORK SERVICE"
},
"log"=>{
"level"=>"information"
},
"tags"=>[
"beat-ext",
"beats_input_codec_plain_applied"
],
"type"=>"redis-input",
"metadata"=>{
"type"=>"_doc",
"beat"=>"winlogbeat",
"version"=>"7.14.0",
"ip_address"=>"..."
},
"process"=>{
"args"=>[
"gpupdate.exe",
"/target:computer"
],
"pe"=>{
"company"=>"Microsoft Corporation",
"original_file_name"=>"GPUpdate.exe",
"imphash"=>"d2466cd4c38ecef8aab0ee78b79fc8b8",
"description"=>"Microsoft® Group Policy Update Utility",
"product"=>"Microsoft® Windows® Operating System",
"file_version"=>"10.0.19041.572 (WinBuild.160101.0800)"
},
"pid"=>14480,
"parent"=>{
"args"=>[
"C:\\WINDOWS\\system32\\svchost.exe",
"-k",
"netsvcs",
"-p",
"-s",
"Schedule"
],
"pid"=>2764,
"command_line"=>"C:\\WINDOWS\\system32\\svchost.exe -k netsvcs -p -s Schedule",
"executable"=>"C:\\Windows\\System32\\svchost.exe",
"name"=>"svchost.exe",
"entity_id"=>"{a3a021f9-4e58-60f0-2b00-000000000b00}"
},
"hash"=>{
"md5"=>"118729dd62b9422d21afe5cebd564f8a",
"sha256"=>"b76ce2bba63bd2949fa6e36fba963379b9d682f7642cd3782d9818fcd30a3e00"
},
"command_line"=>"gpupdate.exe /target:computer",
"executable"=>"C:\\Windows\\System32\\gpupdate.exe",
"name"=>"gpupdate.exe",
"entity_id"=>"{a3a021f9-657f-6114-a9de-d94d01000000}",
"working_directory"=>"C:\\WINDOWS\\system32\\"
},
"host"=>{
"hostname"=>"...",
"mac"=>[
"...",
"...",
"...",
"...",
"..."
],
"os"=>{
"family"=>"windows",
"platform"=>"windows",
"build"=>"19042.1110",
"type"=>"windows",
"kernel"=>"10.0.19041.1110 (WinBuild.160101.0800)",
"version"=>"10.0",
"name"=>"Windows 10 Enterprise"
},
"name"=>"...",
"ip"=>[
"...",
"...",
"...",
"...",
"...",
"...",,
"...",
"...",
"...",
"..."
],
"architecture"="...",
"id"=>"..."
},
"winlog"=>{
"opcode"=>"Info",
"provider_name"=>"Microsoft-Windows-Sysmon",
"computer_name"=>"...",
"version"=>5,
"task"=>"Process Create (rule: ProcessCreate)",
"process"=>{
"thread"=>{
"id"=>15204
},
"pid"=>10112
},
"record_id"=>43577,
"channel"=>"Microsoft-Windows-Sysmon/Operational",
"event_id"=>"1",
"event_data"=>{
"Description"=>"Microsoft® Group Policy Update Utility",
"Product"=>"Microsoft® Windows® Operating System",
"FileVersion"=>"10.0.19041.572 (WinBuild.160101.0800)",
"LogonGuid"=>"{a3a021f9-4e57-60f0-e403-000000000000}",
"TerminalSessionId"=>"0",
"LogonId"=>"0x3e4",
"Company"=>"Microsoft Corporation",
"IntegrityLevel"=>"System"
},
"api"=>"wineventlog",
"user"=>{
"type"=>"User",
"name"=>"SYSTEM",
"identifier"=>"S-1-5-18",
"domain"=>"NT AUTHORITY"
},
"provider_guid"=>"...",
},
"event"=>{
"module"=>"sysmon",
"category"=>[
"process"
],
"created"=>"2021-08-12T00:04:17.126Z",
"type"=>[
"start",
"process_start"
],
"provider"=>"Microsoft-Windows-Sysmon",
"kind"=>"event",
"action"=>"Process Create (rule: ProcessCreate)",
"code"=>"1"
},
"@timestamp"=>2021-08-12T00: 04: 15.445Z,
"agent"=>{
"hostname"=>"...",
"ephemeral_id"=>"...",
"type"=>"winlogbeat",
"version"=>"7.14.0",
"name"=>"...",
"id"=>"..."
},
"hash"=>{
"md5"=>"118729dd62b9422d21afe5cebd564f8a",
"sha256"=>"b76ce2bba63bd2949fa6e36fba963379b9d682f7642cd3782d9818fcd30a3e00",
"imphash"=>"d2466cd4c38ecef8aab0ee78b79fc8b8"
},
"ecs"=>{
"version"=>"1.10.0"
},
"user"=>{
"name"=>"NETWORK SERVICE",
"domain"=>"NT AUTHORITY",
"id"=>"S-1-5-18"
},
"message"=>"Process Create:\nRuleName: -\nUtcTime: 2021-08-12 00:04:15.445\nProcessGuid: {a3a021f9-657f-6114-a9de-d94d01000000}\nProcessId: 14480\nImage: C:\\Windows\\System32\\gpupdate.exe\nFileVersion: 10.0.19041.572 (WinBuild.160101.0800)\nDescription: Microsoft® Group Policy Update Utility\nProduct: Microsoft® Windows® Operating System\nCompany: Microsoft Corporation\nOriginalFileName: GPUpdate.exe\nCommandLine: gpupdate.exe /target:computer\nCurrentDirectory: C:\\WINDOWS\\system32\\\nUser: NT AUTHORITY\\NETWORK SERVICE\nLogonGuid: {a3a021f9-4e57-60f0-e403-000000000000}\nLogonId: 0x3E4\nTerminalSessionId: 0\nIntegrityLevel: System\nHashes: MD5=118729DD62B9422D21AFE5CEBD564F8A,SHA256=B76CE2BBA63BD2949FA6E36FBA963379B9D682F7642CD3782D9818FCD30A3E00,IMPHASH=D2466CD4C38ECEF8AAB0EE78B79FC8B8\nParentProcessGuid: {a3a021f9-4e58-60f0-2b00-000000000b00}\nParentProcessId: 2764\nParentImage: C:\\Windows\\System32\\svchost.exe\nParentCommandLine: C:\\WINDOWS\\system32\\svchost.exe -k netsvcs -p -s Schedule",
"@version"=>"1"
}
],
:response=>{
"index"=>{
"_index"=>"so-beats",
"_type"=>"_doc",
"_id"=>nil,
"status"=>400,
"error"=>{
"type"=>"illegal_argument_exception",
"reason"=>"field [process.pe.description] already exists"
}
}
}
}