I have a stack filebeat > logstash > elasticsearch
Here is my config of filebeat.
filebeat.inputs: - type: log enabled: true paths: - C:\folder\* json.keys_under_root: true output.logstash: hosts: [my.server:5044]
After migrating to filebeat 7.6.4 my log.message stop arriving to elasticsearch but everything else still does. It was obvious that I got a conflict with new ECS.
I went through migration documentation but still can find a proper solution to my problem. I don't use filebeat modules and changing a current log schema aren't an option. I've also tried different processors but no luck either.
Would love some thoughts on how to resolve this.