Elasticsearch input missing [@metadata][_index]

I'll try later when I get back to work!

100% positive. This is VPN log. So even if different packet types return different fields, the whole index is the same, all fields considered.

Yes, when I switch to http input for testing and feed it one of the docs retrieved, it will always work.

I'm gonna try and see if I can convince our infra guys to improve things over there, otherwise I think I'll be stuck =\