-
Notifications
You must be signed in to change notification settings - Fork 76
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[BUG] 2.11 Creating custom log type fails #700
Comments
Should have created this in: https://github.com/opensearch-project/security-analytics-dashboards-plugin could someone move this? |
@opensearch-project/triage Can you please transfer this to the https://github.com/opensearch-project/security-analytics-dashboards-plugin repo? |
Thanks Craig, couldn't make the meeting :) |
Seems like we are trying to overwrite the mappings for the @sbcd90, @eirsep Can one of you looking why that might be happening? |
Analyzer is property of the field in index mapping. currently the issue is that you cannot change the mapping of an existing field. What you need to do if you want to change the mapping of existing documents is reindex those documents to another index with the updated mapping So effectively, we are currently not supporting adding our own mappings. We need the logs to investigate correctly but i have a hunch that this issue is from the query index. Will need to deep dive into the alerting query index logic and explore possibility of how we can copy over the analyzer parameter |
@ict-one-nl can you provide the relevant server logs and stacktrace for this error to enable us to debug this issue. |
Master node:
Second click on the button:
Changed the name, back to:
Does this help? |
@ict-one-nl Can you delete the |
This is kind of a wipe the sheet clean solution and it doesn't solve the root cause. Is there a more elegant way? |
hi @ict-one-nl , we have already created a github issue #708 to handle this scenario correctly. |
That helped, ish. I can create a new log type now. Updating the name of that newly created logtype gives: opensearch-master-nodes-0 opensearch-master-nodes [2023-11-04T20:23:17,414][ERROR][o.o.s.u.SecurityAnalyticsException] [opensearch-master-nodes-0] Security Analytics error: |
hi @ict-one-nl, does this newly created custom log type have any rules? if not, can you please create a custom rule? |
Resolved by above PRs |
What is the bug?
See video:
https://github.com/opensearch-project/security-dashboards-plugin/assets/2643715/79f44dba-f742-46aa-9741-28347f09843b
What is the expected behavior?
A clear and concise description of what you expected to happen.
What is your host/environment?
2.11 default docker container
Do you have any screenshots?
^^
Do you have any additional context?
N/A
The text was updated successfully, but these errors were encountered: