Problem
Logs carrying fields that do not fit the standard UTMStack typed fields are stored under log (a heterogeneous map). OpenSearch dynamic mapping infers a hard type for each key on first sight and rejects any later value that does not fit (mapper_parsing_exception), so the log is lost.
Approach (planned)
- New canonical bag
event replacing log.* / legacy logx.*, mapped as OpenSearch flattened (keyword sub-values, no type inference, no conflicts possible).
- New
controls []string field reserved for compliance control tags (populated later by the compliance orchestrator).
- Rename cascades from the go-sdk proto (Event field 9
log -> event, new field 20 controls) through EventProcessor parsing, UTMStack filters/rules, installer index template, backend SearchUtil (flattened-aware query building), user-auditor, and the frontend (file-management module moves to origin/target canonical fields).
- No reindex: new data uses
event; old log data rides out ILM rotation.
Scope
Coordinated cross-repo change: threatwinds/go-sdk, utmstack/EventProcessor, utmstack/UTMStack (filters, rules, installer, backend, user-auditor, frontend, alerts plugin tests).
Plan: UTMStack repo docs/plans/2026-09-30-event-bag-rename.md.
Problem
Logs carrying fields that do not fit the standard UTMStack typed fields are stored under
log(a heterogeneous map). OpenSearch dynamic mapping infers a hard type for each key on first sight and rejects any later value that does not fit (mapper_parsing_exception), so the log is lost.Approach (planned)
eventreplacinglog.*/ legacylogx.*, mapped as OpenSearch flattened (keyword sub-values, no type inference, no conflicts possible).controls []stringfield reserved for compliance control tags (populated later by the compliance orchestrator).log->event, new field 20controls) through EventProcessor parsing, UTMStack filters/rules, installer index template, backend SearchUtil (flattened-aware query building), user-auditor, and the frontend (file-management module moves to origin/target canonical fields).event; oldlogdata rides out ILM rotation.Scope
Coordinated cross-repo change: threatwinds/go-sdk, utmstack/EventProcessor, utmstack/UTMStack (filters, rules, installer, backend, user-auditor, frontend, alerts plugin tests).
Plan: UTMStack repo
docs/plans/2026-09-30-event-bag-rename.md.