Hello once again,
After configuring decoders recently noticed that I was missing alerts, after checking Filebeat I noticed warnings, example (shortened):
Mar 23 12:06:01 host filebeat[4553]: 2022-03-23T12:06:01.222+0200 WARN [elasticsearch] elasticsearch/client.go:408 Cannot index event publisher.Event{Content:beat.Event{Timestamp:time.Time{wall:0xc086da222649db18, ext:3877549838983, loc:(*time.Location)(0x42417a0)}, Meta:{"pipeline":"filebeat-7.10.2-wazuh-alerts-pipeline"}, Fields:{"agent":{"ephemeral_id":"dbd129b7-805c-4d0f-b2a2-fb24da28b56d"
...
(status=400): {"type":"mapper_parsing_exception","reason":"failed to parse field [data.message] of type [keyword] in document with id '6qI9tn8BO-8Eo70pi__4'. Preview of field's value: '{length=4427, id=cekrc2MFl1iz0EHPTKy0OlItN}'","caused_by":{"type":"illegal_state_exception","reason":"Can't get text on a START_OBJECT at 1:292"}}
Also after checking Index Patterns (not sure if related):
Any ideas how I could solve this?
Thank you in advance