I noticed a lot of Elastic Agent log fields have a question mark and seem unmapped. Imho it would be useful if we can aggregate on these fields. Could the mapping please be updated so these fields can be used properly?
For example in .ds-logs-elastic_agent.filebeat-default-2024.05.30-000037
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.