Could not locate that index-pattern-field (id: "FIELD_NAME") #3758
-
Hello! I'm working on standing up a Security Onion 2 environment (converting from SO1 with a fresh reinstall) and I didn't notice any issues during the installation. At the moment, I have a manager online and 1 forwarding sensors connected to it. I can confirm that the sensor is checking into the manager and that the sensor is seeing logs. However in Kibana/Elastic, none of the tables are populating and only display "Could not locate that index-pattern-field (id: "FIELD_NAME")" Examples: Any ideas how to troubleshoot this? |
Beta Was this translation helpful? Give feedback.
Replies: 6 comments 6 replies
-
Just to confirm that I also experience similar issues ever since I updated my setup to 2.3.40 (manager + heavy node), only I see error in Osquery dashboard.
|
Beta Was this translation helpful? Give feedback.
-
When comparing my production Security Onion deployment with my personal lab, it appears that I've lost all of the Kibana Index Patterns (https:///kibana/app/management/kibana/indexPatterns). If I click into each pattern, I only have 5 entries. Any idea how to restore the patterns? |
Beta Was this translation helpful? Give feedback.
-
@facyber The osquery Kibana error is a different issue - Please run Also - do you have any new osquery data coming in? |
Beta Was this translation helpful? Give feedback.
-
@tcritch05 What version of SO2 are you on? Please run |
Beta Was this translation helpful? Give feedback.
-
Beta Was this translation helpful? Give feedback.
-
@tcritch05 You say you have a Manager & sensor - do you have a search node? That is where the data is actually stored. You could also do a Manager + Search node if you want to combine the node types. |
Beta Was this translation helpful? Give feedback.
@tcritch05 You say you have a Manager & sensor - do you have a search node? That is where the data is actually stored. You could also do a Manager + Search node if you want to combine the node types.