But it ends up writing this host.name: to the index.
As I understand it, this is because in the original json host.name is not written as an object, but as on the screenshot. How to make it to be recorded as event.kind? Has anyone encountered this? Is there a solution for this?
There's an issue on the topic, but after reading it I'm not fully sure if it was fixed on this PR, released at 8.6. Yet worth checking the comments and workarounds mentioned there.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.