Is there a Zeek field to ECS field mapping document? Other than the logtype.yml files which actually do the conversion and renames, I have not been able to find anything. I'm avoiding having to build this mapping from scratch because I imagine it must exist by now.
An example is the duration field in Zeek. In the ECS process, it gets turned into temp.duration (according to connection.yml) and then into event.duration in the ECS pipeline (pipeline.yml)
If you deploy zeek integration with elastic agent, then you can view/edit the ingest pipeline associated with the zeek integration. that is where the data curated prior to persisting to the corresponding log index.