Logstash error „mapper_parsing_exception“

We use an instance of Elastic as part of Security Onion, because of that preconfigured config files exist on the system. Because of that all document fields with the name ‚host‘ will be renamed to ‚beat_host‘ by Logstash.

Logstash refuses to index, because of a field named „beat_host“ in the index mapping declared as an object type, but instead of this type it received an concrete value.

