-
Notifications
You must be signed in to change notification settings - Fork 8.3k
/
mappings.json
103 lines (103 loc) · 2.75 KB
/
mappings.json
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
{
"dynamic": "false",
"properties": {
"@timestamp": {
"type": "date"
},
"tags": {
"ignore_above": 1024,
"type": "keyword",
"meta": {
"isArray": "true"
}
},
"message": {
"norms": false,
"type": "text"
},
"ecs": {
"properties": {
"version": {
"ignore_above": 1024,
"type": "keyword"
}
}
},
"event": {
"properties": {
"action": {
"ignore_above": 1024,
"type": "keyword"
},
"provider": {
"ignore_above": 1024,
"type": "keyword"
},
"start": {
"type": "date"
},
"duration": {
"type": "long"
},
"end": {
"type": "date"
}
}
},
"error": {
"properties": {
"message": {
"norms": false,
"type": "text"
}
}
},
"user": {
"properties": {
"name": {
"fields": {
"text": {
"norms": false,
"type": "text"
}
},
"ignore_above": 1024,
"type": "keyword"
}
}
},
"kibana": {
"properties": {
"server_uuid": {
"type": "keyword",
"ignore_above": 1024
},
"alerting": {
"properties": {
"instance_id": {
"type": "keyword",
"ignore_above": 1024
}
}
},
"saved_objects": {
"properties": {
"namespace": {
"type": "keyword",
"ignore_above": 1024
},
"id": {
"type": "keyword",
"ignore_above": 1024
},
"type": {
"type": "keyword",
"ignore_above": 1024
}
},
"type": "nested"
}
}
}
}
}