Type conflict for client.ip and client.geo.location #14101
-
Version2.4.110 Installation MethodSecurity Onion ISO image Descriptionother (please provide detail below) Installation TypeDistributed Locationon-prem with Internet access Hardware SpecsExceeds minimum requirements CPU64 RAM251G Storage for /558G Storage for /nsm38T Network Traffic Collectiontap Network Traffic Speeds1Gbps to 10Gbps StatusYes, all services on all nodes are running OK Salt StatusNo, there are no failures LogsNo, there are no additional clues DetailHello, I'm encountering type conflicts from my Okta integration. Specifically, the fields client.ip (desired type: ip, received type: keyword) and client.geo.location (desired type: geo_point, received type: object) are causing mapping issues. I am aware of the known issues, and I see that there is now the field okta.client.ip that I assume might have been created in relation to this conflict, but that doesn't solve my issues with client.ip. I have another service that uses client.ip, so this is greatly affecting me. I've tried reindexing, but that just made the Okta indice I reindexed have client.ip as text. I would appreciate any advise on how to address these type conflicts and ensure proper data mapping between my services and Okta? Thank you! Guidelines
|
Beta Was this translation helpful? Give feedback.
Replies: 3 comments 3 replies
-
Which indices are in conflict? If you check in Kibana > Stack Management > Data Views and select logs-* In the Field Type box hit the dropdown and select conflict. If you hit the Conflict hyperlink it should tell you which indices are what data type. |
Beta Was this translation helpful? Give feedback.
-
Beta Was this translation helpful? Give feedback.
-
Created issue #14106 |
Beta Was this translation helpful? Give feedback.
Created issue #14106