I have a rather strange problem. My fleet agents that are either Windows or MacOS will send the network flows just fine, including geoid enrichment:
But the flows send by Linux hosts do not contain any geo ip enrichment anymore. I know this worked some time ago so I am not sure what happened.
I searched for anything destination.geo.country: * and host os linux but no results.
It would be nice if this would work again as some of my detection rules are based on geo ip (e.g. connection of server to suspicious country etc.).
ELK 8.14.0
Fleet Agents (working and not working) are on
8.14.0 as well.
Network Capture Integration v1.1.0 (on all agents).
Any help is appreciated.