You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
elastic-agent: failed to parse field [event.dataset] only accepts values that are equal to the value defined in the mappings [system.process.summary], but got [system.process_summary]\ "}}, dropping event!
#4750
Error reported in elastic-agent log file with debug logging:
Cannot index event publisher.Event{Content:beat.Event{Timestamp:time.Date(2024, time.May, 14, 11, 21, 18, 572370253, time.Local), Meta:{\"input_id\":\"system-metrics\",\"raw_index\":\"metrics-system.process_summary-default\"}failed to parse field [event.dataset] of type [constant_keyword] in document with id 'LaXWdo8B3mT0fKffBUgR'. Preview of field's value: 'system.process_summary'\",\"caused_by\":{\"type\":\"illegal_argument_exception\",\"reason\":\"[constant_keyword] field [event.dataset] only accepts values that are equal to the value defined in the mappings [system.process.summary], but got [system.process_summary]\"}}, dropping event!
If we change the index template to be the generic metrics as per screen shot then data is sent to the index. However changing it to metrics-system.process.summary index template which should be the correct one then fails with the mentioned error.
Using metrics index template
Should be able to use this index template but errors as above
For confirmed bugs, please report:
Version:
Elastic Agent: 8.13.2 running on Kubernetes as daemon set
Elastic deployment: 8.11.3
Steps to Reproduce:
Install elastic agent standalone onto Kubernetes using yaml as provided.
Install k8s integration in Kibana
Check elastic-agents for 400 errors
Snippet from the metrics-system.process.summary Managed index template
failed to parse field [event.dataset] of type [constant_keyword] Preview of field's value: 'system.process_summary'","caused_by":{"type":"illegal_argument_exception","reason":"[constant_keyword] field [event.dataset] only accepts values that are equal to the value defined in the mappings [system.process.summary], but got [system.process_summary]"}}, dropping event!
davidg-datascene
changed the title
failed to parse field [event.dataset] only accepts values that are equal to the value defined in the mappings [system.process.summary], but got [system.process_summary]\ "}}, dropping event!
elastic-agent: failed to parse field [event.dataset] only accepts values that are equal to the value defined in the mappings [system.process.summary], but got [system.process_summary]\ "}}, dropping event!
May 14, 2024
Error reported in elastic-agent log file with debug logging:
If we change the index template to be the generic
metrics
as per screen shot then data is sent to the index. However changing it tometrics-system.process.summary
index template which should be the correct one then fails with the mentioned error.Using metrics index template
Should be able to use this index template but errors as above
For confirmed bugs, please report:
Elastic Agent: 8.13.2 running on Kubernetes as daemon set
Elastic deployment: 8.11.3
Install elastic agent standalone onto Kubernetes using yaml as provided.
Install k8s integration in Kibana
Check elastic-agents for 400 errors
Snippet showing DataStream
Elastic agent standalone yaml
The text was updated successfully, but these errors were encountered: