Select pattern instead of an index

I store log automatically every day into opensearch with patern fortigate-logs%{+YYYY-MM-dd}
Now each day an index will be created for each day.
When I want to create correlation rule, I should choose an index, How can I tell opensearch select pattern instead of an index?

Hi @m_pahlevanzadeh

Have you tried an index alias instead?

Here is more info at Index aliases - OpenSearch Documentation

Looking at Docs, you can specify index patterns as well: Creating correlation rules - OpenSearch Documentation

“Select index dropdown list, specify an index or index pattern…”

something like:

fortigate-logs*

Best,
mj

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.