By default, Winlogbeat would map the winlog.event_data.param*
as keyword. How to map the field to multi-fields keyword and text?
This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
By default, Winlogbeat would map the winlog.event_data.param*
as keyword. How to map the field to multi-fields keyword and text?
This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
© 2020. All Rights Reserved - Elasticsearch
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant logo are trademarks of the Apache Software Foundation in the United States and/or other countries.