Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Google Workspace] - Duplicate Logs in google_workspace.alert #9373

Open
ar3diu opened this issue Mar 15, 2024 · 3 comments
Open

[Google Workspace] - Duplicate Logs in google_workspace.alert #9373

ar3diu opened this issue Mar 15, 2024 · 3 comments
Labels
bug Something isn't working, use only for issues Integration:google_workspace Google Workspace Team:Security-Service Integrations Security Service Integrations Team [elastic/security-service-integrations]

Comments

@ar3diu
Copy link

ar3diu commented Mar 15, 2024

Integration name and version: Google Workspace 2.20.0

This integration writes duplicate log entries in the google_workspace.alert dataset when using the default settings.
I made a post about this back in december: https://elasticstack.slack.com/archives/C02J2JBS0FP/p1702896388318999
But I came across it again today.

image

Another user observed a similar behavior: https://elasticstack.slack.com/archives/C02J2JBS0FP/p1710176601575189

@jamiehynds jamiehynds added Integration:google_workspace Google Workspace Team:Security-Service Integrations Security Service Integrations Team [elastic/security-service-integrations] labels Mar 19, 2024
@elasticmachine
Copy link

Pinging @elastic/security-service-integrations (Team:Security-Service Integrations)

@jamiehynds jamiehynds added the bug Something isn't working, use only for issues label Mar 19, 2024
@narph
Copy link
Contributor

narph commented Jul 5, 2024

related elastic/beats#39859

@ShourieG
Copy link
Contributor

ShourieG commented Jul 5, 2024

Hi @ar3diu, here I can see that the fingerprints are the same, which means the fingerprint processor is working as expected. Elasticsearch should not index documents with same _id more than once. Something seems off here.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working, use only for issues Integration:google_workspace Google Workspace Team:Security-Service Integrations Security Service Integrations Team [elastic/security-service-integrations]
Projects
None yet
Development

No branches or pull requests

5 participants