The index pattern was refreshed successfully in O365 Module

321 views
Skip to first unread message

Michael Reiner

unread,
Jun 30, 2023, 3:15:10 AM6/30/23
to Wazuh mailing list
Hey there.

Everytime I expand an event in the O365 Module, I get the following message:
The index pattern was refreshed successfully.
There were some unknown fields for the current index pattern. You need to refresh the page to apply the changes.

If I ignore the message to expand other entries, after a while the site becomes unresponsive.
Clicking reload does nothing but reloading the page. The message comes back the moment I expand another event.

Othniel Ebolum

unread,
Jun 30, 2023, 11:39:35 AM6/30/23
to Wazuh mailing list
Hi Michael, 

I hope you are doing well. 

To troubleshoot, try Clearing the browser cache and cookies to ensure a clean session.

if the issues persist after this, there may be unknown fields in the index pattern configuration and it may need to be refreshed. 

Refresh the index pattern by selecting the menu icon in the top left corner and navigate to Management -> Stack Management -> Index Patterns -> wazuh-alerts-*. Click the refresh button on that index pattern page as shown below.

you can follow examples made in the Wazuh dashboard header in this blog post: monitoring Linux resource usage with Wazuh

I hope this helps.

Best Regards, 

Michael Reiner

unread,
Jul 11, 2023, 1:57:30 AM7/11/23
to Wazuh mailing list
Hi.

Tried everything. Cleared cached, even tried a new InPrivate session, refreshed the fields, same problem.

Michael Reiner

unread,
Jul 11, 2023, 4:26:29 AM7/11/23
to Wazuh mailing list
It seems to have something to do with parsing the events.

For example:
I have an Audit.AzureActiveDirectory Event.
Field List in the wazuh-alerts-* index pattern shows the Fields:
and
data.office365.DeviceProperties.Value

But the Event shows the field
data.office365.DeviceProperties
as "unknown" field with the content
{
  "Value": "Windows 10",
  "Name": "OS"
},
{
  "Value": "Chrome",
  "Name": "BrowserType"
},
{
  "Value": "False",
  "Name": "IsCompliantAndManaged"
}


Reply all
Reply to author
Forward
0 new messages