[Elasticsearch][Enrich] Policy name field is not correct #6608
Labels
Feature:Stack Monitoring
Stack Monitoring Feature
Integration:elasticsearch
Elasticsearch
Team:Stack Monitoring
Stack Monitoring team [elastic/stack-monitoring]
Summary
For the Elasticsearch enrich data stream, there is a field named
elasticsearch.enrich.executing_policy.name
that displays values such asexecuting enrich policy [users-policy] creating new enrich index [.enrich-users-policy-1687187221242]
:The name of the field suggests that it should hold the value of the policy name, however that is not happening.
Looking at the metricbeat module this field is populated by the corresponding field in the API payload, which is reported as the policy name. Given the metricbeat logic was not touched could it be the API that returns new values ?
The text was updated successfully, but these errors were encountered: