Enyce
1
Anyone ever succed to create a detectors on a datastream ?
While putting the ‘.ds-winlogbeat-*’ index pattern, it triggers an error with:
[security_analytics_exception] null cannot be cast to non-null type kotlin.collections.MutableMap<kotlin.String, kotlin.Any>
adn77
2
I just use winlogbeat
as the index name. The data stream name is basically an alias for a bunch of indices.
Enyce
3
putting my datasteam alias index gives me:
[2023-12-09T19:31:53,582][ERROR][o.o.a.t.TransportIndexMonitorAction] [prd-siem-clusrer-node-1] failed to index doc level queries monitor w7sQUIwBTJLvaV9jlY-1. deleting monitor
system
Closed
5
This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.