Skip to content

[Azure] Reduce degraded documents in auditlogs by raising keyword ignore_above to 8191 - #20131

Closed
shmsr wants to merge 2 commits into
elastic:mainfrom
shmsr:fix/azure-auditlogs-degraded-docs
Closed

shmsr wants to merge 2 commits into
elastic:mainfrom
shmsr:fix/azure-auditlogs-degraded-docs

Conversation

@shmsr

@shmsr shmsr commented Jul 15, 2026 •

Copy link
Copy Markdown
Member

No description provided.

…ded documents

Fleet's strings_as_keyword dynamic template applies ignore_above: 1024 to all
keyword fields. Azure Entra ID audit payloads routinely exceed this limit on
result_description, result_reason, additional_details.value, and the
modified_properties leaf fields (old_value/new_value/display_name), causing
those field values to be silently dropped and documents marked degraded.

Raises ignore_above to 8191 (the safe UTF-8 keyword ceiling; Lucene's hard term
limit is 32766 bytes, 32766/4 = 8191 chars) on the affected fields. The
modified_properties group is also restructured from per-leaf keyword declarations
to a single object_type: keyword template on modified_properties.*.*, working
around a Fleet/EPM limitation where only the first declared leaf under a
doubly-nested wildcard path gets its own dynamic template.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
@shmsr
shmsr requested review from a team as code owners July 15, 2026 08:16
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
@github-actions

Copy link
Copy Markdown
Contributor

Elastic Docs Style Checker (Vale)

Summary: 1 warning found

⚠️ Warnings (1): Fix when the suggestion improves clarity or correctness.
File Line Rule Message
packages/azure/data_stream/auditlogs/fields/fields.yml 115 Elastic.Latinisms Latin terms and abbreviations are a common source of confusion. Use 'for example' instead of 'e.g'.

The Vale linter checks documentation changes against the Elastic Docs style guide. To use Vale locally or report issues, refer to Elastic style guide for Vale.

@shmsr

shmsr commented Jul 15, 2026

Copy link
Copy Markdown
Member Author

Closing — opened prematurely.

@shmsr shmsr closed this Jul 15, 2026
@shmsr
shmsr deleted the fix/azure-auditlogs-degraded-docs branch July 15, 2026 08:17
@elastic-vault-github-plugin-prod

Copy link
Copy Markdown
Contributor

✅ All changelog entries have the correct PR link.

@shmsr
shmsr restored the fix/azure-auditlogs-degraded-docs branch July 15, 2026 08:27
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant