I have an ECK managed Elastic Agent shipping logs to ES. In logs and metrics documents, the host.ip
field has a large list of duplicate IPV6 addresses. An example:
[<Redacted actual IP addresses (which are correct)>,
fe80::ecee:eeff:feee:eeee,
fe80::ecee:eeff:feee:eeee,
fe80::ecee:eeff:feee:eeee,
fe80::ecee:eeff:feee:eeee,
fe80::ecee:eeff:feee:eeee,
fe80::ecee:eeff:feee:eeee,
fe80::ecee:eeff:feee:eeee,
fe80::ecee:eeff:feee:eeee,
fe80::ecee:eeff:feee:eeee,
fe80::ecee:eeff:feee:eeee,
fe80::ecee:eeff:feee:eeee,
fe80::ecee:eeff:feee:eeee,
fe80::ecee:eeff:feee:eeee,
fe80::ecee:eeff:feee:eeee,
fe80::ecee:eeff:feee:eeee,
fe80::ecee:eeff:feee:eeee,
fe80::ecee:eeff:feee:eeee,
fe80::ecee:eeff:feee:eeee,
fe80::ecee:eeff:feee:eeee,
fe80::ecee:eeff:feee:eeee,
fe80::ecee:eeff:feee:eeee,
fe80::ecee:eeff:feee:eeee,
fe80::ecee:eeff:feee:eeee,
fe80::ecee:eeff:feee:eeee,
fe80::ecee:eeff:feee:eeee,
fe80::ecee:eeff:feee:eeee,
fe80::ecee:eeff:feee:eeee,
fe80::ecee:eeff:feee:eeee,
fe80::ecee:eeff:feee:eeee
]
Is there a reason for this, or is this a bug? Where does the Elastic Agent receive this data from?