LME
LME copied to clipboard
Verify fields in parsed logs.
From Adam's comments:
Check if we are loading the elasticsearch ingest node pipelines from the winlogbeat setup command and that logstash is configured to use the ingest node pipelines.
Reference this Slack Canvas discussion: https://dhscisa.enterprise.slack.com/docs/T02QH7E1MHA/F067EAFHZT9
This ticket is also referred to as "update Elastic Schema".