- 
                Notifications
    
You must be signed in to change notification settings  - Fork 25.6k
 
Closed
Labels
:Core/Infra/CoreCore issues without another labelCore issues without another label>bugTeam:Core/InfraMeta label for core/infra teamMeta label for core/infra teamblockerstatefulMarking issues only relevant for stateful releasesMarking issues only relevant for stateful releasesv9.0.0v9.0.1
Description
In 9.0.0-rc1 we identified an issue where system data stream .fleet-actions-results is still problematic after being upgraded from 7.17.28 > 8.18 > 9.0.0-rc1.
Slack thread: https://elastic.slack.com/archives/C8UUBNASY/p1742824896518599
How to reproduce:
- On 7.17.28 instance run osquery queries or endpoint isolate/release action. That saved actions to .fleet-actions-results
 - Upgrade to 8.18.0
 - At this point there is no issue
 - Resolve all ES critical issues - there was over 40 issues that I had to reindex - however none of them was about fleet-actions-results
 - Upgrade to 9.0.0
 - Issue exists.
 
This issue pops out in multiple places, eg. fleet, index management etc. But also breaks other functionalities (eg. those using fleet/agents).
Originally posted by @tomsonpl in #122949
Hi @alexey-ivanov-es, unfortunately another issue occurred with the above mentioned data stream. It was found on 9.0.0-rc1.
Is this still in your ownership, or fleet now?
![]()
{ "statusCode": 500, "error": "Internal Server Error", "message": "illegal_argument_exception\n\tRoot causes:\n\t\tillegal_argument_exception: Data stream(s) [.fleet-actions-results] may not be accessed by product [kibana]" }
Metadata
Metadata
Assignees
Labels
:Core/Infra/CoreCore issues without another labelCore issues without another label>bugTeam:Core/InfraMeta label for core/infra teamMeta label for core/infra teamblockerstatefulMarking issues only relevant for stateful releasesMarking issues only relevant for stateful releasesv9.0.0v9.0.1
