Hi, i tried sending windows logs to our elasticsearch cluster to our already existing winlogbeat template but for some reason these new windows machines are having trouble. For some reason, the data is not showing up in kibana from these new windows hosts. I verified that our logstash machines are receiving the data from the new windows machines with tcpdump.
I checked the logs of one of our elastic data nodes and found this:
[2018-07-11T15:06:11,920][DEBUG][o.e.a.b.TransportShardBulkAction] [winlogbeat-2018-07-11] failed to execute bulk item (index) BulkShardRequest [[winlogbeat-2018-07-11]] containing  requests
org.elasticsearch.index.mapper.MapperParsingException: object mapping for [host] tried to parse field [host] as object, but found a concrete value
I then ran the following command to see the mapping for host:
I can see that the host mapping is of the type "text" but this has not been an issue with previous windows hosts. What is the issue here and how would i go about fixing this?
Thankful for replies.
EDIT: I found that the host field in kibana looks like this:
I only want the "DCC02" part, how would i fix this?