I want to remove some duplicated fileds' value by using remove processor in ingest pipeline. I using Elastic Agent to collect log. The problem is I always got an error in output is: "field [field_name] not present as part of path [field_name]".
I use CEF integration, it has some CEF standard fields and some event.* fields (and more) with the same value. For example, "cef.severity : 3" and "event.severity : 3", "cef.device.vendor: Trend Micro" and "observer.vendor : Trend Micro", etc.
Thankyou for reading. Please help.