Skip to content

[UII] Add index.mapping.ignore_malformed: true to transform index template settings - #232439

Merged
jen-huang merged 1 commit into
elastic:mainfrom
jen-huang:fix/transform-malformed-mappings
Aug 21, 2025
Merged

jen-huang merged 1 commit into
elastic:mainfrom
jen-huang:fix/transform-malformed-mappings

Conversation

@jen-huang

@jen-huang jen-huang commented Aug 20, 2025 •

Copy link
Copy Markdown
Contributor

Summary

Resolves #179445. Does what it says on the tin :)

Release note

Transform index templates installed by Fleet will now have the index.mapping.ignore_malformed: true setting set. This resolves issues where transforms can enter a failed state due to invalid values in the source index.

Checklist

  • Unit or functional tests were updated or added to match the most common scenarios
  • The PR description includes the appropriate Release Notes section, and the correct release_note:* label is applied per the guidelines
  • Review the backport guidelines and apply applicable backport:* labels.

@jen-huang jen-huang self-assigned this Aug 20, 2025
@jen-huang
jen-huang requested a review from a team as a code owner August 20, 2025 21:23
@jen-huang jen-huang added release_note:fix Team:Fleet - DEPRECATED Use Team:streams-ui backport:all-open Backport to all branches that could still receive a release labels Aug 20, 2025
@elasticmachine

Copy link
Copy Markdown
Contributor

Pinging @elastic/fleet (Team:Fleet)

@elasticmachine

Copy link
Copy Markdown
Contributor

💚 Build Succeeded

Metrics [docs]

✅ unchanged

cc @jen-huang

@juliaElastic juliaElastic left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code LGTM.
Should we test that the setting is applied correctly?

@jen-huang
jen-huang merged commit 908e4d8 into elastic:main Aug 21, 2025
@kibanamachine

Copy link
Copy Markdown
Contributor

Starting backport for target branches: 8.17, 8.18, 8.19, 9.0, 9.1

https://github.com/elastic/kibana/actions/runs/17122585965

kibanamachine pushed a commit to kibanamachine/kibana that referenced this pull request Aug 21, 2025
…emplate settings (elastic#232439)

## Summary

Resolves elastic#179445. Does what it says on the tin :)

## Release note
Transform index templates installed by Fleet will now have the
`index.mapping.ignore_malformed: true` setting set. This resolves issues
where transforms can enter a failed state due to invalid values in the
source index.

### Checklist

- [x] [Unit or functional
tests](https://www.elastic.co/guide/en/kibana/master/development-tests.html)
were updated or added to match the most common scenarios
- [x] The PR description includes the appropriate Release Notes section,
and the correct `release_note:*` label is applied per the
[guidelines](https://www.elastic.co/guide/en/kibana/master/contributing.html#kibana-release-notes-process)
- [x] Review the [backport
guidelines](https://docs.google.com/document/d/1VyN5k91e5OVumlc0Gb9RPa3h1ewuPE705nRtioPiTvY/edit?usp=sharing)
and apply applicable `backport:*` labels.

(cherry picked from commit 908e4d8)
@kibanamachine

Copy link
Copy Markdown
Contributor

💔 Some backports could not be created

Status Branch Result
❌ 8.17 Backport failed because of merge conflicts
❌ 8.18 Backport failed because of merge conflicts
❌ 8.19 Backport failed because of merge conflicts
❌ 9.0 Backport failed because of merge conflicts
✅ 9.1

Note: Successful backport PRs will be merged automatically after passing CI.

Manual backport

To create the backport manually run:

node scripts/backport --pr 232439

Questions ?

Please refer to the Backport tool documentation

kibanamachine added a commit that referenced this pull request Aug 21, 2025
…ndex template settings (#232439) (#232453)

# Backport

This will backport the following commits from `main` to `9.1`:
- [[UII] Add `index.mapping.ignore_malformed: true` to transform index
template settings
(#232439)](#232439)

<!--- Backport version: 9.6.6 -->

### Questions ?
Please refer to the [Backport tool
documentation](https://github.com/sorenlouv/backport)

<!--BACKPORT [{"author":{"name":"Jen
Huang","email":"its.jenetic@gmail.com"},"sourceCommit":{"committedDate":"2025-08-21T09:15:25Z","message":"[UII]
Add `index.mapping.ignore_malformed: true` to transform index template
settings (#232439)\n\n## Summary\n\nResolves #179445. Does what it says
on the tin :)\n\n## Release note\nTransform index templates installed by
Fleet will now have the\n`index.mapping.ignore_malformed: true` setting
set. This resolves issues\nwhere transforms can enter a failed state due
to invalid values in the\nsource index.\n\n### Checklist\n\n- [x] [Unit
or
functional\ntests](https://www.elastic.co/guide/en/kibana/master/development-tests.html)\nwere
updated or added to match the most common scenarios\n- [x] The PR
description includes the appropriate Release Notes section,\nand the
correct `release_note:*` label is applied per
the\n[guidelines](https://www.elastic.co/guide/en/kibana/master/contributing.html#kibana-release-notes-process)\n-
[x] Review the
[backport\nguidelines](https://docs.google.com/document/d/1VyN5k91e5OVumlc0Gb9RPa3h1ewuPE705nRtioPiTvY/edit?usp=sharing)\nand
apply applicable `backport:*`
labels.","sha":"908e4d8ccb42a3b2ae8203f0c8072d56a4471862","branchLabelMapping":{"^v9.2.0$":"main","^v(\\d+).(\\d+).\\d+$":"$1.$2"}},"sourcePullRequest":{"labels":["release_note:fix","Team:Fleet","backport:all-open","v9.2.0"],"title":"[UII]
Add `index.mapping.ignore_malformed: true` to transform index template
settings","number":232439,"url":"https://github.com/elastic/kibana/pull/232439","mergeCommit":{"message":"[UII]
Add `index.mapping.ignore_malformed: true` to transform index template
settings (#232439)\n\n## Summary\n\nResolves #179445. Does what it says
on the tin :)\n\n## Release note\nTransform index templates installed by
Fleet will now have the\n`index.mapping.ignore_malformed: true` setting
set. This resolves issues\nwhere transforms can enter a failed state due
to invalid values in the\nsource index.\n\n### Checklist\n\n- [x] [Unit
or
functional\ntests](https://www.elastic.co/guide/en/kibana/master/development-tests.html)\nwere
updated or added to match the most common scenarios\n- [x] The PR
description includes the appropriate Release Notes section,\nand the
correct `release_note:*` label is applied per
the\n[guidelines](https://www.elastic.co/guide/en/kibana/master/contributing.html#kibana-release-notes-process)\n-
[x] Review the
[backport\nguidelines](https://docs.google.com/document/d/1VyN5k91e5OVumlc0Gb9RPa3h1ewuPE705nRtioPiTvY/edit?usp=sharing)\nand
apply applicable `backport:*`
labels.","sha":"908e4d8ccb42a3b2ae8203f0c8072d56a4471862"}},"sourceBranch":"main","suggestedTargetBranches":[],"targetPullRequestStates":[{"branch":"main","label":"v9.2.0","branchLabelMappingKey":"^v9.2.0$","isSourceBranch":true,"state":"MERGED","url":"https://github.com/elastic/kibana/pull/232439","number":232439,"mergeCommit":{"message":"[UII]
Add `index.mapping.ignore_malformed: true` to transform index template
settings (#232439)\n\n## Summary\n\nResolves #179445. Does what it says
on the tin :)\n\n## Release note\nTransform index templates installed by
Fleet will now have the\n`index.mapping.ignore_malformed: true` setting
set. This resolves issues\nwhere transforms can enter a failed state due
to invalid values in the\nsource index.\n\n### Checklist\n\n- [x] [Unit
or
functional\ntests](https://www.elastic.co/guide/en/kibana/master/development-tests.html)\nwere
updated or added to match the most common scenarios\n- [x] The PR
description includes the appropriate Release Notes section,\nand the
correct `release_note:*` label is applied per
the\n[guidelines](https://www.elastic.co/guide/en/kibana/master/contributing.html#kibana-release-notes-process)\n-
[x] Review the
[backport\nguidelines](https://docs.google.com/document/d/1VyN5k91e5OVumlc0Gb9RPa3h1ewuPE705nRtioPiTvY/edit?usp=sharing)\nand
apply applicable `backport:*`
labels.","sha":"908e4d8ccb42a3b2ae8203f0c8072d56a4471862"}}]}]
BACKPORT-->

Co-authored-by: Jen Huang <its.jenetic@gmail.com>
@jen-huang

jen-huang commented Aug 21, 2025 •

Copy link
Copy Markdown
Contributor Author

Should we test that the setting is applied correctly?

@juliaElastic There is a unit test that covers that. Or did you mean elsewhere?

@jen-huang

Copy link
Copy Markdown
Contributor Author

💚 All backports created successfully

Status Branch Result
✅ 9.0
✅ 8.19
✅ 8.18
✅ 8.17

Note: Successful backport PRs will be merged automatically after passing CI.

Questions ?

Please refer to the Backport tool documentation

jen-huang added a commit that referenced this pull request Aug 21, 2025
…ndex template settings (#232439) (#232536)

# Backport

This will backport the following commits from `main` to `9.0`:
- [[UII] Add `index.mapping.ignore_malformed: true` to transform index
template settings
(#232439)](#232439)

<!--- Backport version: 10.0.1 -->

### Questions ?
Please refer to the [Backport tool
documentation](https://github.com/sorenlouv/backport)

<!--BACKPORT [{"author":{"name":"Jen
Huang","email":"its.jenetic@gmail.com"},"sourceCommit":{"committedDate":"2025-08-21T09:15:25Z","message":"[UII]
Add `index.mapping.ignore_malformed: true` to transform index template
settings (#232439)\n\n## Summary\n\nResolves #179445. Does what it says
on the tin :)\n\n## Release note\nTransform index templates installed by
Fleet will now have the\n`index.mapping.ignore_malformed: true` setting
set. This resolves issues\nwhere transforms can enter a failed state due
to invalid values in the\nsource index.\n\n### Checklist\n\n- [x] [Unit
or
functional\ntests](https://www.elastic.co/guide/en/kibana/master/development-tests.html)\nwere
updated or added to match the most common scenarios\n- [x] The PR
description includes the appropriate Release Notes section,\nand the
correct `release_note:*` label is applied per
the\n[guidelines](https://www.elastic.co/guide/en/kibana/master/contributing.html#kibana-release-notes-process)\n-
[x] Review the
[backport\nguidelines](https://docs.google.com/document/d/1VyN5k91e5OVumlc0Gb9RPa3h1ewuPE705nRtioPiTvY/edit?usp=sharing)\nand
apply applicable `backport:*`
labels.","sha":"908e4d8ccb42a3b2ae8203f0c8072d56a4471862","branchLabelMapping":{"^v9.2.0$":"main","^v(\\d+).(\\d+).\\d+$":"$1.$2"}},"sourcePullRequest":{"labels":["release_note:fix","Team:Fleet","backport:all-open","v9.2.0","v9.1.3"],"title":"[UII]
Add `index.mapping.ignore_malformed: true` to transform index template
settings","number":232439,"url":"https://github.com/elastic/kibana/pull/232439","mergeCommit":{"message":"[UII]
Add `index.mapping.ignore_malformed: true` to transform index template
settings (#232439)\n\n## Summary\n\nResolves #179445. Does what it says
on the tin :)\n\n## Release note\nTransform index templates installed by
Fleet will now have the\n`index.mapping.ignore_malformed: true` setting
set. This resolves issues\nwhere transforms can enter a failed state due
to invalid values in the\nsource index.\n\n### Checklist\n\n- [x] [Unit
or
functional\ntests](https://www.elastic.co/guide/en/kibana/master/development-tests.html)\nwere
updated or added to match the most common scenarios\n- [x] The PR
description includes the appropriate Release Notes section,\nand the
correct `release_note:*` label is applied per
the\n[guidelines](https://www.elastic.co/guide/en/kibana/master/contributing.html#kibana-release-notes-process)\n-
[x] Review the
[backport\nguidelines](https://docs.google.com/document/d/1VyN5k91e5OVumlc0Gb9RPa3h1ewuPE705nRtioPiTvY/edit?usp=sharing)\nand
apply applicable `backport:*`
labels.","sha":"908e4d8ccb42a3b2ae8203f0c8072d56a4471862"}},"sourceBranch":"main","suggestedTargetBranches":[],"targetPullRequestStates":[{"branch":"main","label":"v9.2.0","branchLabelMappingKey":"^v9.2.0$","isSourceBranch":true,"state":"MERGED","url":"https://github.com/elastic/kibana/pull/232439","number":232439,"mergeCommit":{"message":"[UII]
Add `index.mapping.ignore_malformed: true` to transform index template
settings (#232439)\n\n## Summary\n\nResolves #179445. Does what it says
on the tin :)\n\n## Release note\nTransform index templates installed by
Fleet will now have the\n`index.mapping.ignore_malformed: true` setting
set. This resolves issues\nwhere transforms can enter a failed state due
to invalid values in the\nsource index.\n\n### Checklist\n\n- [x] [Unit
or
functional\ntests](https://www.elastic.co/guide/en/kibana/master/development-tests.html)\nwere
updated or added to match the most common scenarios\n- [x] The PR
description includes the appropriate Release Notes section,\nand the
correct `release_note:*` label is applied per
the\n[guidelines](https://www.elastic.co/guide/en/kibana/master/contributing.html#kibana-release-notes-process)\n-
[x] Review the
[backport\nguidelines](https://docs.google.com/document/d/1VyN5k91e5OVumlc0Gb9RPa3h1ewuPE705nRtioPiTvY/edit?usp=sharing)\nand
apply applicable `backport:*`
labels.","sha":"908e4d8ccb42a3b2ae8203f0c8072d56a4471862"}},{"branch":"9.1","label":"v9.1.3","branchLabelMappingKey":"^v(\\d+).(\\d+).\\d+$","isSourceBranch":false,"url":"https://github.com/elastic/kibana/pull/232453","number":232453,"state":"MERGED","mergeCommit":{"sha":"fd3254e52650ea987cab7b99d7608863eb32c2a0","message":"[9.1]
[UII] Add `index.mapping.ignore_malformed: true` to transform index
template settings (#232439) (#232453)\n\n# Backport\n\nThis will
backport the following commits from `main` to `9.1`:\n- [[UII] Add
`index.mapping.ignore_malformed: true` to transform index\ntemplate
settings\n(#232439)](https://github.com/elastic/kibana/pull/232439)\n\n\n\n###
Questions ?\nPlease refer to the [Backport
tool\ndocumentation](https://github.com/sorenlouv/backport)\n\n\n\nCo-authored-by:
Jen Huang <its.jenetic@gmail.com>"}}]}] BACKPORT-->

---------

Co-authored-by: kibanamachine <42973632+kibanamachine@users.noreply.github.com>
jen-huang added a commit that referenced this pull request Aug 21, 2025
…index template settings (#232439) (#232537)

# Backport

This will backport the following commits from `main` to `8.19`:
- [[UII] Add `index.mapping.ignore_malformed: true` to transform index
template settings
(#232439)](#232439)

<!--- Backport version: 10.0.1 -->

### Questions ?
Please refer to the [Backport tool
documentation](https://github.com/sorenlouv/backport)

<!--BACKPORT [{"author":{"name":"Jen
Huang","email":"its.jenetic@gmail.com"},"sourceCommit":{"committedDate":"2025-08-21T09:15:25Z","message":"[UII]
Add `index.mapping.ignore_malformed: true` to transform index template
settings (#232439)\n\n## Summary\n\nResolves #179445. Does what it says
on the tin :)\n\n## Release note\nTransform index templates installed by
Fleet will now have the\n`index.mapping.ignore_malformed: true` setting
set. This resolves issues\nwhere transforms can enter a failed state due
to invalid values in the\nsource index.\n\n### Checklist\n\n- [x] [Unit
or
functional\ntests](https://www.elastic.co/guide/en/kibana/master/development-tests.html)\nwere
updated or added to match the most common scenarios\n- [x] The PR
description includes the appropriate Release Notes section,\nand the
correct `release_note:*` label is applied per
the\n[guidelines](https://www.elastic.co/guide/en/kibana/master/contributing.html#kibana-release-notes-process)\n-
[x] Review the
[backport\nguidelines](https://docs.google.com/document/d/1VyN5k91e5OVumlc0Gb9RPa3h1ewuPE705nRtioPiTvY/edit?usp=sharing)\nand
apply applicable `backport:*`
labels.","sha":"908e4d8ccb42a3b2ae8203f0c8072d56a4471862","branchLabelMapping":{"^v9.2.0$":"main","^v(\\d+).(\\d+).\\d+$":"$1.$2"}},"sourcePullRequest":{"labels":["release_note:fix","Team:Fleet","backport:all-open","v9.2.0","v9.1.3"],"title":"[UII]
Add `index.mapping.ignore_malformed: true` to transform index template
settings","number":232439,"url":"https://github.com/elastic/kibana/pull/232439","mergeCommit":{"message":"[UII]
Add `index.mapping.ignore_malformed: true` to transform index template
settings (#232439)\n\n## Summary\n\nResolves #179445. Does what it says
on the tin :)\n\n## Release note\nTransform index templates installed by
Fleet will now have the\n`index.mapping.ignore_malformed: true` setting
set. This resolves issues\nwhere transforms can enter a failed state due
to invalid values in the\nsource index.\n\n### Checklist\n\n- [x] [Unit
or
functional\ntests](https://www.elastic.co/guide/en/kibana/master/development-tests.html)\nwere
updated or added to match the most common scenarios\n- [x] The PR
description includes the appropriate Release Notes section,\nand the
correct `release_note:*` label is applied per
the\n[guidelines](https://www.elastic.co/guide/en/kibana/master/contributing.html#kibana-release-notes-process)\n-
[x] Review the
[backport\nguidelines](https://docs.google.com/document/d/1VyN5k91e5OVumlc0Gb9RPa3h1ewuPE705nRtioPiTvY/edit?usp=sharing)\nand
apply applicable `backport:*`
labels.","sha":"908e4d8ccb42a3b2ae8203f0c8072d56a4471862"}},"sourceBranch":"main","suggestedTargetBranches":[],"targetPullRequestStates":[{"branch":"main","label":"v9.2.0","branchLabelMappingKey":"^v9.2.0$","isSourceBranch":true,"state":"MERGED","url":"https://github.com/elastic/kibana/pull/232439","number":232439,"mergeCommit":{"message":"[UII]
Add `index.mapping.ignore_malformed: true` to transform index template
settings (#232439)\n\n## Summary\n\nResolves #179445. Does what it says
on the tin :)\n\n## Release note\nTransform index templates installed by
Fleet will now have the\n`index.mapping.ignore_malformed: true` setting
set. This resolves issues\nwhere transforms can enter a failed state due
to invalid values in the\nsource index.\n\n### Checklist\n\n- [x] [Unit
or
functional\ntests](https://www.elastic.co/guide/en/kibana/master/development-tests.html)\nwere
updated or added to match the most common scenarios\n- [x] The PR
description includes the appropriate Release Notes section,\nand the
correct `release_note:*` label is applied per
the\n[guidelines](https://www.elastic.co/guide/en/kibana/master/contributing.html#kibana-release-notes-process)\n-
[x] Review the
[backport\nguidelines](https://docs.google.com/document/d/1VyN5k91e5OVumlc0Gb9RPa3h1ewuPE705nRtioPiTvY/edit?usp=sharing)\nand
apply applicable `backport:*`
labels.","sha":"908e4d8ccb42a3b2ae8203f0c8072d56a4471862"}},{"branch":"9.1","label":"v9.1.3","branchLabelMappingKey":"^v(\\d+).(\\d+).\\d+$","isSourceBranch":false,"url":"https://github.com/elastic/kibana/pull/232453","number":232453,"state":"MERGED","mergeCommit":{"sha":"fd3254e52650ea987cab7b99d7608863eb32c2a0","message":"[9.1]
[UII] Add `index.mapping.ignore_malformed: true` to transform index
template settings (#232439) (#232453)\n\n# Backport\n\nThis will
backport the following commits from `main` to `9.1`:\n- [[UII] Add
`index.mapping.ignore_malformed: true` to transform index\ntemplate
settings\n(#232439)](https://github.com/elastic/kibana/pull/232439)\n\n\n\n###
Questions ?\nPlease refer to the [Backport
tool\ndocumentation](https://github.com/sorenlouv/backport)\n\n\n\nCo-authored-by:
Jen Huang <its.jenetic@gmail.com>"}}]}] BACKPORT-->

---------

Co-authored-by: kibanamachine <42973632+kibanamachine@users.noreply.github.com>
jen-huang added a commit that referenced this pull request Aug 21, 2025
…index template settings (#232439) (#232543)

# Backport

This will backport the following commits from `main` to `8.17`:
- [[UII] Add `index.mapping.ignore_malformed: true` to transform index
template settings
(#232439)](#232439)

<!--- Backport version: 10.0.1 -->

### Questions ?
Please refer to the [Backport tool
documentation](https://github.com/sorenlouv/backport)

<!--BACKPORT [{"author":{"name":"Jen
Huang","email":"its.jenetic@gmail.com"},"sourceCommit":{"committedDate":"2025-08-21T09:15:25Z","message":"[UII]
Add `index.mapping.ignore_malformed: true` to transform index template
settings (#232439)\n\n## Summary\n\nResolves #179445. Does what it says
on the tin :)\n\n## Release note\nTransform index templates installed by
Fleet will now have the\n`index.mapping.ignore_malformed: true` setting
set. This resolves issues\nwhere transforms can enter a failed state due
to invalid values in the\nsource index.\n\n### Checklist\n\n- [x] [Unit
or
functional\ntests](https://www.elastic.co/guide/en/kibana/master/development-tests.html)\nwere
updated or added to match the most common scenarios\n- [x] The PR
description includes the appropriate Release Notes section,\nand the
correct `release_note:*` label is applied per
the\n[guidelines](https://www.elastic.co/guide/en/kibana/master/contributing.html#kibana-release-notes-process)\n-
[x] Review the
[backport\nguidelines](https://docs.google.com/document/d/1VyN5k91e5OVumlc0Gb9RPa3h1ewuPE705nRtioPiTvY/edit?usp=sharing)\nand
apply applicable `backport:*`
labels.","sha":"908e4d8ccb42a3b2ae8203f0c8072d56a4471862","branchLabelMapping":{"^v9.2.0$":"main","^v(\\d+).(\\d+).\\d+$":"$1.$2"}},"sourcePullRequest":{"labels":["release_note:fix","Team:Fleet","backport:all-open","v9.2.0","v9.1.3"],"title":"[UII]
Add `index.mapping.ignore_malformed: true` to transform index template
settings","number":232439,"url":"https://github.com/elastic/kibana/pull/232439","mergeCommit":{"message":"[UII]
Add `index.mapping.ignore_malformed: true` to transform index template
settings (#232439)\n\n## Summary\n\nResolves #179445. Does what it says
on the tin :)\n\n## Release note\nTransform index templates installed by
Fleet will now have the\n`index.mapping.ignore_malformed: true` setting
set. This resolves issues\nwhere transforms can enter a failed state due
to invalid values in the\nsource index.\n\n### Checklist\n\n- [x] [Unit
or
functional\ntests](https://www.elastic.co/guide/en/kibana/master/development-tests.html)\nwere
updated or added to match the most common scenarios\n- [x] The PR
description includes the appropriate Release Notes section,\nand the
correct `release_note:*` label is applied per
the\n[guidelines](https://www.elastic.co/guide/en/kibana/master/contributing.html#kibana-release-notes-process)\n-
[x] Review the
[backport\nguidelines](https://docs.google.com/document/d/1VyN5k91e5OVumlc0Gb9RPa3h1ewuPE705nRtioPiTvY/edit?usp=sharing)\nand
apply applicable `backport:*`
labels.","sha":"908e4d8ccb42a3b2ae8203f0c8072d56a4471862"}},"sourceBranch":"main","suggestedTargetBranches":[],"targetPullRequestStates":[{"branch":"main","label":"v9.2.0","branchLabelMappingKey":"^v9.2.0$","isSourceBranch":true,"state":"MERGED","url":"https://github.com/elastic/kibana/pull/232439","number":232439,"mergeCommit":{"message":"[UII]
Add `index.mapping.ignore_malformed: true` to transform index template
settings (#232439)\n\n## Summary\n\nResolves #179445. Does what it says
on the tin :)\n\n## Release note\nTransform index templates installed by
Fleet will now have the\n`index.mapping.ignore_malformed: true` setting
set. This resolves issues\nwhere transforms can enter a failed state due
to invalid values in the\nsource index.\n\n### Checklist\n\n- [x] [Unit
or
functional\ntests](https://www.elastic.co/guide/en/kibana/master/development-tests.html)\nwere
updated or added to match the most common scenarios\n- [x] The PR
description includes the appropriate Release Notes section,\nand the
correct `release_note:*` label is applied per
the\n[guidelines](https://www.elastic.co/guide/en/kibana/master/contributing.html#kibana-release-notes-process)\n-
[x] Review the
[backport\nguidelines](https://docs.google.com/document/d/1VyN5k91e5OVumlc0Gb9RPa3h1ewuPE705nRtioPiTvY/edit?usp=sharing)\nand
apply applicable `backport:*`
labels.","sha":"908e4d8ccb42a3b2ae8203f0c8072d56a4471862"}},{"branch":"9.1","label":"v9.1.3","branchLabelMappingKey":"^v(\\d+).(\\d+).\\d+$","isSourceBranch":false,"url":"https://github.com/elastic/kibana/pull/232453","number":232453,"state":"MERGED","mergeCommit":{"sha":"fd3254e52650ea987cab7b99d7608863eb32c2a0","message":"[9.1]
[UII] Add `index.mapping.ignore_malformed: true` to transform index
template settings (#232439) (#232453)\n\n# Backport\n\nThis will
backport the following commits from `main` to `9.1`:\n- [[UII] Add
`index.mapping.ignore_malformed: true` to transform index\ntemplate
settings\n(#232439)](https://github.com/elastic/kibana/pull/232439)\n\n\n\n###
Questions ?\nPlease refer to the [Backport
tool\ndocumentation](https://github.com/sorenlouv/backport)\n\n\n\nCo-authored-by:
Jen Huang <its.jenetic@gmail.com>"}}]}] BACKPORT-->
jen-huang added a commit that referenced this pull request Aug 21, 2025
…index template settings (#232439) (#232541)

# Backport

This will backport the following commits from `main` to `8.18`:
- [[UII] Add `index.mapping.ignore_malformed: true` to transform index
template settings
(#232439)](#232439)

<!--- Backport version: 10.0.1 -->

### Questions ?
Please refer to the [Backport tool
documentation](https://github.com/sorenlouv/backport)

<!--BACKPORT [{"author":{"name":"Jen
Huang","email":"its.jenetic@gmail.com"},"sourceCommit":{"committedDate":"2025-08-21T09:15:25Z","message":"[UII]
Add `index.mapping.ignore_malformed: true` to transform index template
settings (#232439)\n\n## Summary\n\nResolves #179445. Does what it says
on the tin :)\n\n## Release note\nTransform index templates installed by
Fleet will now have the\n`index.mapping.ignore_malformed: true` setting
set. This resolves issues\nwhere transforms can enter a failed state due
to invalid values in the\nsource index.\n\n### Checklist\n\n- [x] [Unit
or
functional\ntests](https://www.elastic.co/guide/en/kibana/master/development-tests.html)\nwere
updated or added to match the most common scenarios\n- [x] The PR
description includes the appropriate Release Notes section,\nand the
correct `release_note:*` label is applied per
the\n[guidelines](https://www.elastic.co/guide/en/kibana/master/contributing.html#kibana-release-notes-process)\n-
[x] Review the
[backport\nguidelines](https://docs.google.com/document/d/1VyN5k91e5OVumlc0Gb9RPa3h1ewuPE705nRtioPiTvY/edit?usp=sharing)\nand
apply applicable `backport:*`
labels.","sha":"908e4d8ccb42a3b2ae8203f0c8072d56a4471862","branchLabelMapping":{"^v9.2.0$":"main","^v(\\d+).(\\d+).\\d+$":"$1.$2"}},"sourcePullRequest":{"labels":["release_note:fix","Team:Fleet","backport:all-open","v9.2.0","v9.1.3"],"title":"[UII]
Add `index.mapping.ignore_malformed: true` to transform index template
settings","number":232439,"url":"https://github.com/elastic/kibana/pull/232439","mergeCommit":{"message":"[UII]
Add `index.mapping.ignore_malformed: true` to transform index template
settings (#232439)\n\n## Summary\n\nResolves #179445. Does what it says
on the tin :)\n\n## Release note\nTransform index templates installed by
Fleet will now have the\n`index.mapping.ignore_malformed: true` setting
set. This resolves issues\nwhere transforms can enter a failed state due
to invalid values in the\nsource index.\n\n### Checklist\n\n- [x] [Unit
or
functional\ntests](https://www.elastic.co/guide/en/kibana/master/development-tests.html)\nwere
updated or added to match the most common scenarios\n- [x] The PR
description includes the appropriate Release Notes section,\nand the
correct `release_note:*` label is applied per
the\n[guidelines](https://www.elastic.co/guide/en/kibana/master/contributing.html#kibana-release-notes-process)\n-
[x] Review the
[backport\nguidelines](https://docs.google.com/document/d/1VyN5k91e5OVumlc0Gb9RPa3h1ewuPE705nRtioPiTvY/edit?usp=sharing)\nand
apply applicable `backport:*`
labels.","sha":"908e4d8ccb42a3b2ae8203f0c8072d56a4471862"}},"sourceBranch":"main","suggestedTargetBranches":[],"targetPullRequestStates":[{"branch":"main","label":"v9.2.0","branchLabelMappingKey":"^v9.2.0$","isSourceBranch":true,"state":"MERGED","url":"https://github.com/elastic/kibana/pull/232439","number":232439,"mergeCommit":{"message":"[UII]
Add `index.mapping.ignore_malformed: true` to transform index template
settings (#232439)\n\n## Summary\n\nResolves #179445. Does what it says
on the tin :)\n\n## Release note\nTransform index templates installed by
Fleet will now have the\n`index.mapping.ignore_malformed: true` setting
set. This resolves issues\nwhere transforms can enter a failed state due
to invalid values in the\nsource index.\n\n### Checklist\n\n- [x] [Unit
or
functional\ntests](https://www.elastic.co/guide/en/kibana/master/development-tests.html)\nwere
updated or added to match the most common scenarios\n- [x] The PR
description includes the appropriate Release Notes section,\nand the
correct `release_note:*` label is applied per
the\n[guidelines](https://www.elastic.co/guide/en/kibana/master/contributing.html#kibana-release-notes-process)\n-
[x] Review the
[backport\nguidelines](https://docs.google.com/document/d/1VyN5k91e5OVumlc0Gb9RPa3h1ewuPE705nRtioPiTvY/edit?usp=sharing)\nand
apply applicable `backport:*`
labels.","sha":"908e4d8ccb42a3b2ae8203f0c8072d56a4471862"}},{"branch":"9.1","label":"v9.1.3","branchLabelMappingKey":"^v(\\d+).(\\d+).\\d+$","isSourceBranch":false,"url":"https://github.com/elastic/kibana/pull/232453","number":232453,"state":"MERGED","mergeCommit":{"sha":"fd3254e52650ea987cab7b99d7608863eb32c2a0","message":"[9.1]
[UII] Add `index.mapping.ignore_malformed: true` to transform index
template settings (#232439) (#232453)\n\n# Backport\n\nThis will
backport the following commits from `main` to `9.1`:\n- [[UII] Add
`index.mapping.ignore_malformed: true` to transform index\ntemplate
settings\n(#232439)](https://github.com/elastic/kibana/pull/232439)\n\n\n\n###
Questions ?\nPlease refer to the [Backport
tool\ndocumentation](https://github.com/sorenlouv/backport)\n\n\n\nCo-authored-by:
Jen Huang <its.jenetic@gmail.com>"}}]}] BACKPORT-->

---------

Co-authored-by: kibanamachine <42973632+kibanamachine@users.noreply.github.com>
@juliaElastic

Copy link
Copy Markdown
Contributor

Should we test that the setting is applied correctly?

@juliaElastic There is a unit test that covers that. Or did you mean elsewhere?

@jen-huang I mean to test e2e manually that a malformed mapping is ignored in a transform

@jen-huang

Copy link
Copy Markdown
Contributor Author

@jen-huang I mean to test e2e manually that a malformed mapping is ignored in a transform

Ah ok. Yes, I was able to test this by installing MISP (the package reported in original issue), adding a few documents with correct + malformed fields, and tested that the the transform does not error out.

kcreddy added a commit to elastic/integrations that referenced this pull request Sep 3, 2025
…15129)

In current pipeline, the empty strings inside raw data 
can create several malformed fields which are indexed 
into transform source indices due to the default setting: 
"index.mapping.ignore_malformed: true".
Since this setting is "false" inside transform's destination 
indices, the transform fails during index operation.

This PR adds script processor to remove null and 
empty strings inside raw data and not ingest them into 
the source indices avoiding malformed data at source.

PR[1] has the fix for setting the default 
"index.mapping.ignore_malformed: true"
inside transform's destination indices as well.

[1]: elastic/kibana#232439
tehbooom pushed a commit to tehbooom/integrations that referenced this pull request Nov 19, 2025
…lastic#15129)

In current pipeline, the empty strings inside raw data 
can create several malformed fields which are indexed 
into transform source indices due to the default setting: 
"index.mapping.ignore_malformed: true".
Since this setting is "false" inside transform's destination 
indices, the transform fails during index operation.

This PR adds script processor to remove null and 
empty strings inside raw data and not ingest them into 
the source indices avoiding malformed data at source.

PR[1] has the fix for setting the default 
"index.mapping.ignore_malformed: true"
inside transform's destination indices as well.

[1]: elastic/kibana#232439
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Fleet] Setup index.mapping.ignore_malformed in transforms too

4 participants