Create detectors on datastream

Anyone ever succed to create a detectors on a datastream ?

While putting the ‘.ds-winlogbeat-*’ index pattern, it triggers an error with:

[security_analytics_exception] null cannot be cast to non-null type kotlin.collections.MutableMap<kotlin.String, kotlin.Any>

I just use winlogbeat as the index name. The data stream name is basically an alias for a bunch of indices.

putting my datasteam alias index gives me:

[2023-12-09T19:31:53,582][ERROR][o.o.a.t.TransportIndexMonitorAction] [prd-siem-clusrer-node-1] failed to index doc level queries monitor w7sQUIwBTJLvaV9jlY-1. deleting monitor

Up

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.