I'm running 7.16.1 for everything.
I have a question on osquery exported fields.
From this URL: Osquery Manager | Elastic Docs
It states that fields like
interface_details.ibytes should be mapped as ibytes, "keyword, number.long"
When I imported it via fleet, osquery packs. With a simple
query: select * from interface_details;
From the kibana gui on the retrieved data.
All the osquery.idrops , ipackets etc are mapped as text fields.
I thought it was suppose to be mapped as number.long?
Or am I missing something?