Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[BUG] Missing indices / datastreams in Configure logs scan #1329

Open
Psych0meter opened this issue Sep 26, 2024 · 1 comment
Open

[BUG] Missing indices / datastreams in Configure logs scan #1329

Psych0meter opened this issue Sep 26, 2024 · 1 comment
Labels
bug Something isn't working

Comments

@Psych0meter
Copy link

What is the bug?
I only have access to security-auditlog-* indices in Select Index/Aliases in Configure logs scan

How can one reproduce the bug?
Steps to reproduce the behavior:

  1. Go to 'Security Analytics --> Threat Intelligence --> Configure scan'
  2. Click on 'Select Indexes/Aliases'
  3. Datastreams and indices starting with '.' are not displayed

What is the expected behavior?
A clear and concise description of what you expected to happen.

What is your host/environment?

  • OS: Debian 12
  • Version 2.16 and 2.17
  • Plugins

Do you have any additional context?
It seems that there is an issue with Datastreams and Indices starting with . (so it's impossible to add indices created by datastreams)
It's recommended to use Aliases and Datastreams, but none of them are displayed in the dropdown list...
[Aliases](https://opensearch.org/docs/latest/im-plugin/index-alias) and [data streams](https://opensearch.org/docs/latest/im-plugin/data-streams/) are recommended for optimal threat intel scans.

@Psych0meter Psych0meter added bug Something isn't working untriaged labels Sep 26, 2024
@dblock dblock removed the untriaged label Oct 14, 2024
@dblock
Copy link
Member

dblock commented Oct 14, 2024

[Catch All Triage - 1, 2, 3, 4]

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working
Projects
None yet
Development

No branches or pull requests

2 participants