Hello there,
we want to use the ECS log format for our new applications. We already use datastreams with index templates and predefined mappings and I was wondering if we need to write a new mapping for ECS or if there is an existing mapping for all ECS fields that can be used?
On the other hand: Is it even necessary to provide a mapping for ECS or does elasticsearch detect it "automagically" if there is a field with "ecs.version"?
Glad for any help or advice! Thanks!