Skip to content

[BUG] Mapper not found: [linux] #432

@paasi6666

Description

@paasi6666

What is the bug?
When defining a new detector and selecting the "System Logs" type, the "Configure field mapping" are empty.

How can one reproduce the bug?
Steps to reproduce the behavior:

  1. Go to Security Analytics>Detectors>Create detector
  2. Select any index
  3. Click on 'System logs':

image

  1. See that 'Configure field mapping' is empty
  2. When following the link (mappings/view?indexName=index_*&ruleTopic=linux), following message is displayed:

{"ok":false,"error":"[illegal_argument_exception] Mapper not found: [linux]"}

What is the expected behavior?
Like the other types (Azure logs for example):

image

Also, when following the link:
{"ok":true,"response":{"properties":{},"unmapped_index_fields":

What is your host/environment?

  • OS: Centos7
  • Opensearch Version: 2.7.0
  • Opensearch-Dashboards Version: 2.7.0

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions