# MS Exchange integration field mapped incorrectly

**URL:** <https://discuss.elastic.co/t/ms-exchange-integration-field-mapped-incorrectly/368271>\
**Category:** Elastic Agent\
**Created:** [October 4, 2024, 8:21pm UTC](https://discuss.elastic.co/t/ms-exchange-integration-field-mapped-incorrectly/368271 "2024-10-04T20:21:43Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![rugenl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rugenl/32/12887_2.png) [@rugenl](https://discuss.elastic.co/u/rugenl)\
**Post date:** [October 4, 2024, 8:21pm UTC](https://discuss.elastic.co/t/ms-exchange-integration-field-mapped-incorrectly/368271/1 "2024-10-04T20:21:43Z")

</div>

I just started using the MS Exchange integration and found the message tracking field microsoft \> exchange \> relatedrecipientaddress is mapped as an IP, but contains email addresses like bugs@cartoons.fun. I think it's a bug, it looks like it should be a keyword.

I don't know whether to just edit the template, of it updates will overwrite any change.

Any thoughts?

---

<div class="post-metadata">

**Author:** ![erikg](https://avatars.discourse-cdn.com/v4/letter/e/91b2a8/32.png) [@erikg](https://discuss.elastic.co/u/erikg)\
**Post date:** [October 4, 2024, 8:35pm UTC](https://discuss.elastic.co/t/ms-exchange-integration-field-mapped-incorrectly/368271/2 "2024-10-04T20:35:45Z")

</div>

I think you should submit a Github bug issue in the Integrations repo:  
[Issues · elastic/integrations (github.com)](https://github.com/elastic/integrations/issues)

---

<div class="post-metadata">

**Author:** ![rugenl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rugenl/32/12887_2.png) [@rugenl](https://discuss.elastic.co/u/rugenl)\
**Post date:** [October 4, 2024, 8:58pm UTC](https://discuss.elastic.co/t/ms-exchange-integration-field-mapped-incorrectly/368271/3 "2024-10-04T20:58:49Z")

</div>

I had looked at github, but couldn't find the right repo. Thanks, I'll do that, but it will be awhile before I can get the doc for all the fields on that form.

---

<div class="post-metadata">

**Author:** ![erikg](https://avatars.discourse-cdn.com/v4/letter/e/91b2a8/32.png) [@erikg](https://discuss.elastic.co/u/erikg)\
**Post date:** [October 4, 2024, 9:59pm UTC](https://discuss.elastic.co/t/ms-exchange-integration-field-mapped-incorrectly/368271/4 "2024-10-04T21:59:07Z")

</div>

Ah yeah I bet,  
Perhaps just blank issue?  
[New Issue (github.com)](https://github.com/elastic/integrations/issues/new?template=Blank+issue)

---

<div class="post-metadata">

**Author:** ![rugenl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rugenl/32/12887_2.png) [@rugenl](https://discuss.elastic.co/u/rugenl)\
**Post date:** [October 24, 2024, 3:23pm UTC](https://discuss.elastic.co/t/ms-exchange-integration-field-mapped-incorrectly/368271/5 "2024-10-24T15:23:19Z")

</div>

Updating before this closes; issue opened [[Exchange Server] message tracking field relatedrecipientaddress incorrect mapping · Issue #11335 · elastic/integrations · GitHub](https://github.com/elastic/integrations/issues/11335)
