Just hit this on my latest pipeline build! 😅 My Cribl stream was dropping events destined for Elasticsearch with a `strict_mapping` error.
The error log pointed to a field Elasticsearch didn't recognize because of a new data source. Even with dynamic mapping enabled, the "strict" setting in the index template was rejecting it.
The fix was simple: I updated my Elasticsearch destination config in Cribl. Under the `Advanced Settings`, I added `?op_type=create` to the `Extra Query Parameters` field. This makes the write operation non-idempotent and bypasses the strict mapping check for new fields. A temporary patch while we update the index template properly.
Hope this saves someone a few minutes of head-scratching! Anyone else run into this and have a different solution?
measure twice, ship once