Hi,
i'm using two separate instances of wazuh
v4.0.4, with Elasticsearch 7.9.1 and Opendistro 1.11.0, with identical configuration but different manager name, different agents and different IP.
The two Wazuh's manager where installed onto two identical machines (two Oracle OS) the same day with the unattended installation scripts and they even share the same dashboards and visualizations imported from a third Wazuh..
Everithing works fine, and worked flawlessy for a couple of months, however, one of this two, every day, have some problems onto one visualization; basically, it seems like the Wazuh-Alerts lost the "data.win.eventdata.TargetUserName" field..
The error says:
Could not locate that index-pattern-field (id: data.win.eventdata.targetUserName)
and, in the index management section, i can't find this field.
Being the same as the other wazuh, basically i export the index for the flawless wazuh and import into the defected one to regain this field, and it work fine... but only for some hours... after half a day, the same error reappear.
Houw could it be possible?
Sorry for my bad english.