# \[Elastic 8.5.2\] bug in ingestion pipeline?

**URL:** <https://discuss.elastic.co/t/elastic-8-5-2-bug-in-ingestion-pipeline/322231>\
**Category:** Elasticsearch\
**Created:** [December 30, 2022, 6:28pm UTC](https://discuss.elastic.co/t/elastic-8-5-2-bug-in-ingestion-pipeline/322231 "2022-12-30T18:28:51Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Pierre\_LANCASTRE](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pierre_lancastre/32/113702_2.png) [@Pierre\_LANCASTRE](https://discuss.elastic.co/u/Pierre_LANCASTRE)\
**Post date:** [December 30, 2022, 6:28pm UTC](https://discuss.elastic.co/t/elastic-8-5-2-bug-in-ingestion-pipeline/322231/1 "2022-12-30T18:28:51Z")

</div>

Hi,  
For the context, I ve got an Elasticagent on my rsyslog which forwards raw udp log to my Elasticstack (running as standalone).

I've defined a K-V action in the pipeline to split the message and create the different key=value pairs. When I take a document in the pipeline menu, i got no error and all awaited variables are there.

But, when coming back to the observability, the logs with the "data" key are not visible. below a log sample :

LOG NOK :  
\<14\>1 2022-12-30T16:16:57+01:00 wab sshproxy 12283 - - [SSH Session] session\_id="185639b138cb0a1c00505683f34b" client\_ip="192.168.200.1" target\_ip="rsyslog.secnumcloud" user="toto" device="RSYSLOG" service="SSH" account="toto" type="KBD\_INPUT" data="sudo -i"

LOG OK :  
\<14\>1 2022-12-30T16:16:25+01:00 wab sshproxy 12283 - - [SSH Session] session\_id="185639b138cb0a1c00505683f34b" client\_ip="192.168.200.2" target\_ip="rsyslog.secnumcloud" user="toto" device="RSYSLOG" service="SSH" account="toto" type="SESSION\_ESTABLISHED\_SUCCESSFULLY"

If I remove my K-V, I can find all the logs.

The K-V options are the following :  
Field split : " (?=[a-z\_-]+=)"  
value split : "="

I'm wondering if I could have any hidden special character or if having "data" as a key could be forbidden by design. I ve tried to rename the key "data" in "charac", but i still get the same issue.

I'm really confused since when running the pipeline into the pipeline config menu it's working.

Could someone help me please ? I've probably missed something. Thanks

Pierre

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [December 30, 2022, 7:11pm UTC](https://discuss.elastic.co/t/elastic-8-5-2-bug-in-ingestion-pipeline/322231/2 "2022-12-30T19:11:41Z")

</div>

Hi @Pierre_LANCASTRE Welcome to the community!

Well I think you ran into a tough one...

Can you show us the whole KV processor definition just so we can see...

So I _suspect_ Here is the issue ... `user` [is an object in ECS](https://www.elastic.co/guide/en/ecs/current/ecs-user.html) and you are trying to just set it as a field.

> [@Pierre\_LANCASTRE](#):
>
> user="toto"

Which explains

> [@Pierre\_LANCASTRE](#):
>
> I'm really confused since when running the pipeline into the pipeline config menu it's working.

Which just simulates / tests the pipeline but does not actually write the document which would then have a mapper parsing exception.

You could test this by actually trying to POST a document with the pipeline

```auto
POST myindex/_doc/?pipeline=my-pipeline
{
   "message" : "your message" 
}

```

You will probably get a mapping exception...

So after the KV you will need to [rename](https://www.elastic.co/guide/en/elasticsearch/reference/8.5/rename-processor.html) the `user` field to either

`user.name`  
or  
`user.id`

so it is compliant...

---

<div class="post-metadata">

**Author:** ![Pierre\_LANCASTRE](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pierre_lancastre/32/113702_2.png) [@Pierre\_LANCASTRE](https://discuss.elastic.co/u/Pierre_LANCASTRE)\
**Post date:** [January 1, 2023, 7:12pm UTC](https://discuss.elastic.co/t/elastic-8-5-2-bug-in-ingestion-pipeline/322231/3 "2023-01-01T19:12:57Z")

</div>

Hi Stephen,

Thanks a lot for your feedback. Your answer helped to return on one solution : prefix the generated fields by something. I think the first time the name I used needed to have alread an existing object (I forgot to do that). So there, I configured the K-V to prefix the fields with "event." so I got event.data, event.user, etc. and it works

Thanks a lot for your help

BR

Pierre L

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 29, 2023, 7:13pm UTC](https://discuss.elastic.co/t/elastic-8-5-2-bug-in-ingestion-pipeline/322231/4 "2023-01-29T19:13:17Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
