Skip to content

Commit 9c55100

Browse files
philippkahrflorent-leborgneleemthompo
authored andcommitted
Update logs-data-stream.md to include runtime fields compability issues (elastic#3517)
Co-authored-by: florent-leborgne <[email protected]> Co-authored-by: Liam Thompson <[email protected]>
1 parent d79fe45 commit 9c55100

File tree

1 file changed

+3
-0
lines changed

1 file changed

+3
-0
lines changed

manage-data/data-store/data-streams/logs-data-stream.md

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -188,3 +188,6 @@ The `logsdb` index mode uses the following settings:
188188
## Upgrade to logsdb [upgrade-to-logsdb]
189189

190190
Starting with version `9.0`, `logsdb` index mode is automatically applied to data streams with names matching the pattern `logs-*-*`. This default applies to Elasticsearch instances created in version `9.0` or later, as well as older instances that had no data streams matching the pattern `logs-*-*`. For the latter, you can still [configure `logsdb` index mode manually](#how-to-use-logsds).
191+
192+
## Runtime fields [runtime-fields]
193+
There are some compatibility issues with runtime fields which are commonly used within Rules for Elastic Security. Refer to [](/solutions/security/detect-and-alert/using-logsdb-index-mode-with-elastic-security.md#logsdb-runtime-fields) for more information.

0 commit comments

Comments
 (0)