# Wrong Mapping of ECS fields on fleet-managed datastreams causing multiple issues

**URL:** <https://discuss.elastic.co/t/wrong-mapping-of-ecs-fields-on-fleet-managed-datastreams-causing-multiple-issues/305014>\
**Category:** Beats\
**Tags:** fleet, elastic-agent\
**Created:** [May 18, 2022, 4:27am UTC](https://discuss.elastic.co/t/wrong-mapping-of-ecs-fields-on-fleet-managed-datastreams-causing-multiple-issues/305014 "2022-05-18T04:27:37Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Bryan\_Hamilton](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bryan_hamilton/32/82111_2.png) [@Bryan\_Hamilton](https://discuss.elastic.co/u/Bryan_Hamilton)\
**Post date:** [May 18, 2022, 4:27am UTC](https://discuss.elastic.co/t/wrong-mapping-of-ecs-fields-on-fleet-managed-datastreams-causing-multiple-issues/305014/1 "2022-05-18T04:27:37Z")

</div>

Hi,

We recently migrated part of our environment from beats to the elastic-agent managed by fleet integrations. While this makes agent management very easy, it introduced a lot of mapping issues which then cause search filters and SIEM rules to fail due to mapping inconsistencies accross datastreams, expecially when the starting index is `logs-*`.

Let's take a field like source.ip an example:  
running `GET logs-*/_mapping/field/source.ip` shows mixed mappings

![image](https://us1.discourse-cdn.com/elastic/original/3X/d/f/df28252e16aa2f754f54e1a281137dc35e389ab6.png)

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/2/5/25a1082b35c44236bcbb889d75dbcf028ccc79c2.png)

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/1/0/109d9843e9ab7c61c340ff7a6e1c97078bf59881.png)

looking at a dataset **system.system** , the index template is composed of the following component templates

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/c/5/c50862620fcd70dfe5fbcc20a47edee830022314.png)

with its mappings coming from **logs-system.system@package** , which looks like this:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/6/c/6c8c9188a255b572cd5946eb7071c34fa5436d78.png)

There is no other component templates with mapping for other ECS fields, which would explain the inconsistency.

Many other ECS fields have the same issue due to lack of mapping on the index template.  
`GET logs-*/_mapping/field/dns.resolved_ip`

![image](https://us1.discourse-cdn.com/elastic/original/3X/d/4/d497d2a7e477f514275a15053e0041dc5398b642.png)

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/4/5/45ee21fded6f51d6d26ffc39dc010cf435e7e425.png)

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/6/1/61d858aec12a38538ccb93cd4c7566a5a0e6bdee.png)

With these beeing fleet managed, when we try adding the mapping ourselves, it works but gets overwritten when an elastic update is applied to the integration.

Most of our SIEM rules querying these inconsistent fields just don't work ☹.

It would be useful to have an ecs mapping component template applied to all fleet managed datastreams.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 15, 2022, 6:28am UTC](https://discuss.elastic.co/t/wrong-mapping-of-ecs-fields-on-fleet-managed-datastreams-causing-multiple-issues/305014/2 "2022-06-15T06:28:06Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
