I'm running a test cluster and a production cluster, metricbeats is one of the things posting data into both of these.
In the metricbeat-* index pattern on my dev cluster the
host field is searchable and aggregatable but on my production cluster I have a
host field (searchable and analyzed) and a
host.keyword (searchable and aggregatable) alongside it. I don't know how that got there, I haven't been messing with the mapping API or the template files.
Because my dev/prod clusters have different fields it's messing up my ElastAlert YAML, one references host and the other needs host.keyword.
Which setup is correct according to MetricBeat defaults and how do I get them in sync?