rock-dashboards
rock-dashboards copied to clipboard
event.duration incorrectly reported
Running RockNSM 2.4.2 Modified Logstash output to send data to Elastic Cloud ECS pipeline
While running initial tests using the ECS pipeline I found event.duration reporting time scales that made no sense and did not match results obtained with the non-ECS pipeline. The same version of RockNSM was being used in both instances. The old fields show proper decimal values showing expected durations for connections and dns requests. While the ECS acquired values are being given in hours, days and years. No changes to the filters have been made in logstash. I am wondering if this is a general issue or something I am only encountering before attempting to fix the problem. I have provided screenshots comparing the duration fields obtained from both the original and followed by the ECS. I encountered the issue while monitoring data of web activity on my laptop to verify that my pipeline was functioning properly.