Yet Another Elastic SIEM Not Showing Hosts

This sounds similar to this issue here maybe?

You can use those instructions to check your mappings. What can happen is if you have a beat that is constantly pushing data and don't shut it down before re-doing your mappings, that beat will still usually "win" by pushing a new piece of data into the system and then you get default dynamic mappings all over again which are going to mostly text fields which is not what we want.

When re-doing mappings you have to:

  • ensure everything is shut down and nothing gets back in
  • Remove your mappings
  • Push your explicit beats mappings
  • Turn on your beats again
  • Check your mappings one more time to make sure the right parts are still keyword and not textfield