Hello! Do somebody know what does mean this error? (Per Bucket Monitor)

#! Deprecation: [interval] on [date_histogram] is deprecated, use [fixed_interval] or [calendar_interval] in the future.
{
"_id": "xWdjA5sBoeamHjFYf3Hw",
"_version": 31,
"_seq_no": 37920,
"_primary_term": 39,
"monitor": {
"type": "monitor",
"schema_version": 8,
"name": "MS Windows: Успешное подключение одной УЗ с разных IP адресов",
"monitor_type": "bucket_level_monitor",
"enabled": true,
"enabled_time": 1768918477969,
"schedule": {
"period": {
"interval": 1,
"unit": "MINUTES"
}
},
"inputs": [
{
"search": {
"indices": [
"wazuh-alerts-current"
],
"query": {
"size": 0,
"query": {
"bool": {
"filter": [
{
"range": {
"@timestamp": {
"from": "{{period_end}}||-300s",
"to": "{{period_end}}",
"include_lower": true,
"include_upper": true,
"format": "epoch_millis",
"boost": 1
}
}
},
],
"must_not": [
{
"terms": {
"data.win.eventdata.targetUserName": [
"ANONYMOUS LOGON",
"АНОНИМНЫЙ ВХОД"
],
"boost": 1
}
}
],
"adjust_pure_negative": true,
"boost": 1
}
},
"aggregations": {
"composite_agg": {
"composite": {
"size": 20,
"sources": [
{
"data.win.eventdata.targetUserName": {
"terms": {
"field": "data.win.eventdata.targetUserName",
"missing_bucket": false,
"order": "asc"
}
}
}
]
},
"aggregations": {
"unique_ips": {
"cardinality": {
"field": "data.win.eventdata.ipAddress"
}
}
}
}
}
}
}
}
],
"triggers": [
{
"bucket_level_trigger": {
"id": "xGdjA5sBoeamHjFYf3Hq",
"name": "MS Windows: Успешное подключение одной УЗ с разных рабочих станций",
"severity": "2",
"condition": {
"buckets_path": {
"uniq": "unique_ips.value"
},
"parent_bucket_path": "composite_agg",
"script": {
"source": "params.uniq > 4",
"lang": "painless"
},
"gap_policy": "skip"
},
"actions": [
{
"id": "notification327539",
"name": "Send to Kaiten",
"destination_id": "xF8JnJoBovKpQ5b8ijIc",
"message_template": {
"source": """{
"title": "Целевая УЗ: {{#ctx.newAlerts}}{{bucket_keys}}{{/ctx.newAlerts}}",
"tags": ["{{ctx.monitor.name}}"],
"links": [
{
"url": "{{#ctx.newAlerts}}https://wazuh.ovp.ru/app/data-explorer/discover#?_a=(discover:(columns:!(_source),isDirty:!f,sort:!()),metadata:(indexPattern:'wazuh-alerts-*',view:discover))&_g=(filters:!(),refreshInterval:(pause:!t,value:0),time:(from:now-1h,to:now))&_q=(filters:!(('$state':(store:appState),meta:(alias:!n,disabled:!f,index:'wazuh-alerts-*',key:rule.id,negate:!f,params:(query:'100014'),type:phrase),query:(match_phrase:(rule.id:'100014'))),('$state':(store:appState),meta:(alias:!n,disabled:!f,index:'wazuh-alerts-*',key:data.win.eventdata.targetUserName,negate:!f,params:(query:{{bucket_keys}}),type:phrase),query:(match_phrase:(data.win.eventdata.targetUserName:{{bucket_keys}})))),query:(language:kuery,query:'')){{/ctx.newAlerts}}",
"description": "Открыть в Wazuh Discover"
}
],
"description": "\n- 🚨 Событие: {{ctx.monitor.name}}\n- 🚨 Приоритет: {{ctx.trigger.severity}}\n- ⏳ Время начала: {{ctx.periodStart}} UTC\n- ⌛ Время окончания: {{ctx.periodEnd}} UTC {{#ctx.newAlerts}}\n---{{#sample_documents.0}}\n- 🙎♂️ Инициатор: {{_source.data.win.eventdata.targetUserName}}\n- 👁🗨 Агент: {{_source.agent.name}}\n- 🔎 Правило: {{_source.rule.description}} (id: {{_source.rule.id}})\n- 🚨 Level: {{_source.rule.level}}\n [Открыть в Wazuh](https://wazuh.ovp.ru/app/data-explorer/discover#?_a=(discover:(columns:!(_source),isDirty:!t,sort:!()),metadata:(indexPattern:'wazuh-alerts-*',view:discover))&_q=(filters:!(('$state':(store:appState),meta:(alias:!n,disabled:!f,index:'wazuh-alerts-*',key:rule.id,negate:!f,params:(query:'100014'),type:phrase),query:(match_phrase:(rule.id:'100014'))),('$state':(store:appState),meta:(alias:!n,disabled:!f,index:'wazuh-alerts-*',key:data.win.eventdata.targetUserName,negate:!f,params:(query:{{bucket_keys}}),type:phrase),query:(match_phrase:(data.win.eventdata.targetUserName:{{bucket_keys}})))),query:(language:kuery,query:''))&_g=(filters:!(),refreshInterval:(pause:!t,value:0),time:(from:now-24h,to:now)))\n---{{/sample_documents.0}}{{/ctx.newAlerts}}"
}
""",
"lang": "mustache"
},
"throttle_enabled": false,
"subject_template": {
"source": "Alerting Notification action",
"lang": "mustache"
},
"action_execution_policy": {
"action_execution_scope": {
"per_alert": {
"actionable_alerts": [
"NEW"
]
}
}
}
},
{
"id": "notification810195",
"name": "Send to Yandex",
"destination_id": "X4L_5pkBS6jN-8SDuQFi",
"message_template": {
"source": """{
"chat_id": "1/0/191a25c4-b3f1-4e10-a6b1-a412c17b48e5",
"text": "WAZUH\n\n- 🚨 Событие: {{ctx.monitor.name}}\n- 🚨 Приоритет: {{ctx.trigger.severity}}\n- ⏳ Время начала: {{ctx.periodStart}} UTC\n- ⌛ Время окончания: {{ctx.periodEnd}} UTC {{#ctx.newAlerts}}\n---{{#sample_documents.0}}\n- 🙎♂️ Инициатор: {{_source.data.win.eventdata.targetUserName}}\n- 👁🗨 Агент: {{_source.agent.name}}\n- 🔎 Правило: {{_source.rule.description}} (id: {{_source.rule.id}})\n- 🚨 Level: {{_source.rule.level}}\n [Открыть в Wazuh](https://wazuh.ovp.ru/app/data-explorer/discover#?_a=(discover:(columns:!(_source),isDirty:!t,sort:!()),metadata:(indexPattern:'wazuh-alerts-*',view:discover))&_q=(filters:!(('$state':(store:appState),meta:(alias:!n,disabled:!f,index:'wazuh-alerts-*',key:rule.id,negate:!f,params:(query:'100014'),type:phrase),query:(match_phrase:(rule.id:'100014'))),('$state':(store:appState),meta:(alias:!n,disabled:!f,index:'wazuh-alerts-*',key:data.win.eventdata.targetUserName,negate:!f,params:(query:{{bucket_keys}}),type:phrase),query:(match_phrase:(data.win.eventdata.targetUserName:{{bucket_keys}})))),query:(language:kuery,query:''))&_g=(filters:!(),refreshInterval:(pause:!t,value:0),time:(from:now-24h,to:now)))\n---{{/sample_documents.0}}{{/ctx.newAlerts}}"
}
""",
"lang": "mustache"
},
"throttle_enabled": false,
"subject_template": {
"source": "Alerting Notification action",
"lang": "mustache"
},
"action_execution_policy": {
"action_execution_scope": {
"per_alert": {
"actionable_alerts": [
"NEW"
]
}
}
}
},
{
"id": "notification225546",
"name": "Send to TG",
"destination_id": "tAAOOpoBAqvA3MNHy-lM",
"message_template": {
"source": """{
"chat_id": "-1002403153612",
"text": "WAZUH\n\n- 🚨 Событие: {{ctx.monitor.name}}\n- 🚨 Приоритет: {{ctx.trigger.severity}}\n- ⏳ Время начала: {{ctx.periodStart}} UTC\n- ⌛ Время окончания: {{ctx.periodEnd}} UTC {{#ctx.newAlerts}}\n---{{#sample_documents.0}}\n- 🙎♂️ Инициатор: {{_source.data.win.eventdata.targetUserName}}\n- 👁🗨 Агент: {{_source.agent.name}}\n- 🔎 Правило: {{_source.rule.description}} (id: {{_source.rule.id}})\n- 🚨 Level: {{_source.rule.level}}\n [Открыть в Wazuh](https://wazuh.ovp.ru/app/data-explorer/discover#?_a=(discover:(columns:!(_source),isDirty:!t,sort:!()),metadata:(indexPattern:'wazuh-alerts-*',view:discover))&_q=(filters:!(('$state':(store:appState),meta:(alias:!n,disabled:!f,index:'wazuh-alerts-*',key:rule.id,negate:!f,params:(query:'100014'),type:phrase),query:(match_phrase:(rule.id:'100014'))),('$state':(store:appState),meta:(alias:!n,disabled:!f,index:'wazuh-alerts-*',key:data.win.eventdata.targetUserName,negate:!f,params:(query:{{bucket_keys}}),type:phrase),query:(match_phrase:(data.win.eventdata.targetUserName:{{bucket_keys}})))),query:(language:kuery,query:''))&_g=(filters:!(),refreshInterval:(pause:!t,value:0),time:(from:now-24h,to:now)))\n---{{/sample_documents.0}}{{/ctx.newAlerts}}"
}
""",
"lang": "mustache"
},
"throttle_enabled": false,
"subject_template": {
"source": "Alerting Notification action",
"lang": "mustache"
},
"action_execution_policy": {
"action_execution_scope": {
"per_alert": {
"actionable_alerts": [
"NEW"
]
}
}
}
}
]
}
}
],
"last_update_time": 1768918477969,
"data_sources": {
"query_index": ".opensearch-alerting-queries",
"findings_index": ".opensearch-alerting-finding-history-write",
"findings_index_pattern": "<.opensearch-alerting-finding-history-{now/d}-1>",
"alerts_index": ".opendistro-alerting-alerts",
"alerts_history_index": ".opendistro-alerting-alert-history-write",
"alerts_history_index_pattern": "<.opendistro-alerting-alert-history-{now/d}-1>",
"comments_index": ".opensearch-alerting-comments-history-write",
"comments_index_pattern": "<.opensearch-alerting-comments-history-{now/d}-1>",
"query_index_mappings_by_type": {},
"findings_enabled": false
},
"delete_query_index_in_every_run": false,
"should_create_single_alert_for_findings": false,
"owner": "alerting"
},
"associated_workflows": []
}
Hi,
Hi,