Skip to content

[Rule Tuning] Fix Generic Logs index in ESQL rules #5425

@Samirbous

Description

@Samirbous

Description

ES|QL rules with generic logs search query scopefrom logs-* may fail if there are conflicting field types or missing fields.

https://github.com/search?q=repo%3Aelastic%2Fdetection-rules+%22from+logs-*%22+path%3A%2F%5Erules%5C%2Fcross-platform%5C%2F%2F&type=code

Review telem in the next 2/3 weeks for this rule #5416 (fixed by using specific index patterns), if no issues replicate to the other impacted rules.

Metadata

Metadata

Assignees

Labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions