I'm running into an issue parsing cloudtrail logs from filebeat. I am getting this error from the the ecs logs.
WARN [elasticsearch] elasticsearch/client.go:408 Cannot index event publisher.Event{Content:beat.Event{Timestamp:time.Time{wall:0x12db7cb9, ext:63766894617, loc:(*time.Location)(nil)}, Meta:{"_id":"2d2e682040-000000106410","pipeline":"filebeat-7.11.2-aws-cloudtrail-pipeline"}
I've recently enabled organization level logging. It appears as though this has not been working for sometime now. Any help with this issue would be greatly appreciated. It says
{"type":"illegal_argument_exception","reason":"Limit of total fields [1000] has been exceeded"}
At the bottom of the error, as well, but I've updated the limit to 2000.
Is there a way to modify the filebeat.yml so that the indicies can be configured like so?
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.