Hello,
The Infoblox rsa module has 'a lot of room for improvement'.. Multiple fields are very badly parsed. For example a small extract of the network.interface.name field :
As you can see there are multiple issues here.. And that is just the tip of the iceberg. Is this a module developed by Elastic? Can I make a GitHub issue to ask for some improvements please? As in it's current state, I prefer to keep using my own Logstash pipeline. (which is not ecs compliant)
Willem