I've recently noticed an issue where I lose fields/mappings if I refresh the field list to add a newly parsed field in Kibana. The logs I have are coming from Filebeat and not only have the Filebeat fields, but custom fields parsed out from events from Filebeat. I currently have a template for Logstash to use upon writing to ES in /etc/logstash/, and I have also inserted the same template into ES with the curl command.
Again, I am still receiving the logs from Filebeat and syslog with those newly parsed fields with the yellow warning icon saying that there is no cached mapping for the field. If anyone could offer any assistance, it would be greatly appreciated.