Really need some help here. I am trying to use the Kibana SIEM Function; in particular the network function.
I have mapped all my fields to ECS standard but for some reason it is returning 'Data Fetch Failure' and returns "[failed to parse date field  with format [strict_date_optional_time]]"
The only field that I currently have that has an epoch time is called "time_of_log". (There are two time fields: @timestamp represents when the logs was ingested and time_of_log represents when the log was made). To convert the epoch time frame I used the logstash data plugin to make sure the indices realise its format. This method works in the Discover Section but Kibana SIEM will not work?
This is a snippet of my Logstash Pipeline
This is the Kibana SIEM function:
As you can tell the map function is working, but it won't parse any of the data?