- I am using Filebeat Azure module to fetch activity logs and sign-in logs.
- Logstash is running between Filebeat and Elasticsearch and pushing data to a custom index
cloud-audit-azure. Using a custom index to store data purposefully as we want to use index pattern
cloud-audit*having indexes such as
- I copied its ingest pipeline and using the same to parse data.
- after seeing
source.geo.location.londata type as
numberI tried changing it to
geo_pointfrom mapping but no luck
- when changed to
geo_point, cloud-audit-azure was visible in Maps visualization but it was letting me select only one of
Here is the pipeline file if you would like to see :