Opensearch: 2.6.0
Opensearch-Dashboards: 2.6.0
Hi Everyone,
trying to get Document Level Alerting for our ECS based Logs running. Unfortunately i never get any findings even for the most simple queries (Extraction or Gui Based Monitor).
Using the Query on the _search API is working fine.
{
"description": "Monitor Failed Logins to Switches",
"queries": [
{
"id": "failed_logon_events",
"name": "failed_logon_events",
"query": "event.outcome:\"failure\"",
"tags": [
"failed_logon"
]
}
]
}
Tried this on 3 Fresh Installations and always the same outcome. Index is using ECS Mappings if this is relevant.
with best regards,
Kevin
Some Logs from DEBUG Output of *.alerting
[2023-03-16T19:05:45,995][DEBUG][o.o.a.u.DocLevelMonitorQueries] [ntsv25] Node in traverse: {domain={type=keyword, ignore_above=1024}, email={type=keyword, ignore_above=1024}, full_name={type=keyword, ignore_above=1024, fields={text={type=text, norms=false}}}, group={properties={domain={type=keyword, ignore_above=1024}, id={type=keyword, ignore_above=1024}, name={type=keyword, ignore_above=1024}}}, hash={type=keyword, ignore_above=1024}, id={type=keyword, ignore_above=1024}, name={type=keyword, ignore_above=1024, fields={text={type=text, norms=false}}}, roles={type=keyword, ignore_above=1024}}
[2023-03-16T19:05:45,995][DEBUG][o.o.a.u.DocLevelMonitorQueries] [ntsv25] Node in traverse: {domain={type=keyword, ignore_above=1024}, id={type=keyword, ignore_above=1024}, name={type=keyword, ignore_above=1024}}
[2023-03-16T19:05:45,995][DEBUG][o.o.a.u.DocLevelMonitorQueries] [ntsv25] Node in traverse: {domain={type=keyword, ignore_above=1024}, email={type=keyword, ignore_above=1024}, full_name={type=keyword, ignore_above=1024, fields={text={type=text, norms=false}}}, group={properties={domain={type=keyword, ignore_above=1024}, id={type=keyword, ignore_above=1024}, name={type=keyword, ignore_above=1024}}}, hash={type=keyword, ignore_above=1024}, id={type=keyword, ignore_above=1024}, name={type=keyword, ignore_above=1024, fields={text={type=text, norms=false}}}, roles={type=keyword, ignore_above=1024}}
[2023-03-16T19:05:45,995][DEBUG][o.o.a.u.DocLevelMonitorQueries] [ntsv25] Node in traverse: {domain={type=keyword, ignore_above=1024}, id={type=keyword, ignore_above=1024}, name={type=keyword, ignore_above=1024}}
[2023-03-16T19:05:45,995][DEBUG][o.o.a.u.DocLevelMonitorQueries] [ntsv25] Node in traverse: {domain={type=keyword, ignore_above=1024}, id={type=keyword, ignore_above=1024}, name={type=keyword, ignore_above=1024}}
[2023-03-16T19:05:45,995][DEBUG][o.o.a.u.DocLevelMonitorQueries] [ntsv25] Node in traverse: {domain={type=keyword, ignore_above=1024}, email={type=keyword, ignore_above=1024}, full_name={type=keyword, ignore_above=1024, fields={text={type=text, norms=false}}}, group={properties={domain={type=keyword, ignore_above=1024}, id={type=keyword, ignore_above=1024}, name={type=keyword, ignore_above=1024}}}, hash={type=keyword, ignore_above=1024}, id={type=keyword, ignore_above=1024}, name={type=keyword, ignore_above=1024, fields={text={type=text, norms=false}}}, roles={type=keyword, ignore_above=1024}}
[2023-03-16T19:05:45,995][DEBUG][o.o.a.u.DocLevelMonitorQueries] [ntsv25] Node in traverse: {domain={type=keyword, ignore_above=1024}, id={type=keyword, ignore_above=1024}, name={type=keyword, ignore_above=1024}}
[2023-03-16T19:05:45,996][DEBUG][o.o.a.u.DocLevelMonitorQueries] [ntsv25] Node in traverse: {device={properties={name={type=keyword, ignore_above=1024}}}, name={type=keyword, ignore_above=1024}, original={type=keyword, ignore_above=1024, fields={text={type=text, norms=false}}}, os={properties={family={type=keyword, ignore_above=1024}, full={type=keyword, ignore_above=1024, fields={text={type=text, norms=false}}}, kernel={type=keyword, ignore_above=1024}, name={type=keyword, ignore_above=1024, fields={text={type=text, norms=false}}}, platform={type=keyword, ignore_above=1024}, type={type=keyword, ignore_above=1024}, version={type=keyword, ignore_above=1024}}}, version={type=keyword, ignore_above=1024}}
[2023-03-16T19:05:45,996][DEBUG][o.o.a.u.DocLevelMonitorQueries] [ntsv25] Node in traverse: {name={type=keyword, ignore_above=1024}}
[2023-03-16T19:05:45,996][DEBUG][o.o.a.u.DocLevelMonitorQueries] [ntsv25] Node in traverse: {family={type=keyword, ignore_above=1024}, full={type=keyword, ignore_above=1024, fields={text={type=text, norms=false}}}, kernel={type=keyword, ignore_above=1024}, name={type=keyword, ignore_above=1024, fields={text={type=text, norms=false}}}, platform={type=keyword, ignore_above=1024}, type={type=keyword, ignore_above=1024}, version={type=keyword, ignore_above=1024}}
[2023-03-16T19:05:45,996][DEBUG][o.o.a.u.DocLevelMonitorQueries] [ntsv25] Node in traverse: {category={type=keyword, ignore_above=1024}, classification={type=keyword, ignore_above=1024}, description={type=keyword, ignore_above=1024, fields={text={type=text, norms=false}}}, enumeration={type=keyword, ignore_above=1024}, id={type=keyword, ignore_above=1024}, reference={type=keyword, ignore_above=1024}, report_id={type=keyword, ignore_above=1024}, scanner={properties={vendor={type=keyword, ignore_above=1024}}}, score={properties={base={type=float}, environmental={type=float}, temporal={type=float}, version={type=keyword, ignore_above=1024}}}, severity={type=keyword, ignore_above=1024}}
[2023-03-16T19:05:45,996][DEBUG][o.o.a.u.DocLevelMonitorQueries] [ntsv25] Node in traverse: {vendor={type=keyword, ignore_above=1024}}
[2023-03-16T19:05:45,996][DEBUG][o.o.a.u.DocLevelMonitorQueries] [ntsv25] Node in traverse: {base={type=float}, environmental={type=float}, temporal={type=float}, version={type=keyword, ignore_above=1024}}
[2023-03-16T19:05:46,169][DEBUG][o.o.a.c.JobSweeper ] [ntsv25] Not a valid job type in document AEGZ64YBZlLLy0xXiVIG-metadata to sweep.
[2023-03-16T19:05:46,178][DEBUG][o.o.a.MonitorMetadataService] [ntsv25] Successfully upserted MonitorMetadata:AEGZ64YBZlLLy0xXiVIG-metadata