Hi
I am hoping someone can shed some light on why these alerts are not appearing in the dashboard on my version 4.9
This is some of the log output
WARN [elasticsearch] elasticsearch/client.go:408 Cannot index event publisher.Event{Content:beat.Event{Timestamp:time.Time{wall:0xc1b2c2be18769b81, ext:154562571082333, loc:(*time.Location)(0x42417a0)}, Meta:{"pipeline":"filebeat-7.10.2-wazuh-alerts-pipeline"}, Fields:{"agent":{"ephemeral_id"
Private:file.State{Id:"native::2621596-64513", PrevId:"", Finished:false, Fileinfo:(*os.fileStat)(0xc00097c750), Source:"/var/ossec/logs/alerts/alerts.json", Offset:613025534, Timestamp:time.Time{wall:0xc1b2a05df909f35f, ext:119362117609534, loc:(*time.Location)(0x42417a0)}, TTL:-1, Type:"log", Meta:map[string]string(nil), FileStateOS:file.StateOS{Inode:0x28009c, Device:0xfc01}, IdentifierName:"native"}, TimeSeries:false}, Flags:0x1, Cache:publisher.EventCache{m:common.MapStr(nil)}} (status=400): {"type":"mapper_parsing_exception","reason":"failed to parse field [data.status] of type [keyword] in document with id 'i9BQBJIB6xJ1x5_eEgtE'. Preview of field's value: '{failureReason=Other., errorCode=0, additionalDetails=null}'","caused_by":{"type":"illegal_state_exception","reason":"Can't get text on a START_OBJECT at 1:4720"}}
"azure-ad-graph\",\"azure_aad_tag\":\"microsoft-entra_id\"},\"location\":\"Azure\"}","service":{"type":"wazuh"}}, Private:file.State{Id:"native::2621596-64513", PrevId:"", Finished:false, Fileinfo:(*os.fileStat)(0xc00097c750), Source:"/var/ossec/logs/alerts/alerts.json", Offset:612969746, Timestamp:time.Time{wall:0xc1b2a05df909f35f, ext:119362117609534, loc:(*time.Location)(0x42417a0)}, TTL:-1, Type:"log", Meta:map[string]string(nil), FileStateOS:file.StateOS{Inode:0x28009c, Device:0xfc01}, IdentifierName:"native"}, TimeSeries:false}, Flags:0x1, Cache:publisher.EventCache{m:common.MapStr(nil)}} (status=400): {"type":"mapper_parsing_exception","reason":"failed to parse field [data.status] of type [keyword] in document with id 'M-VQBJIBV6LNgm7NDkRf'. Preview of field's value: '{failureReason=Other., errorCode=0, additionalDetails=null}'","caused_by":{"type":"illegal_state_exception","reason":"Can't get text on a START_OBJECT at 1:4632"}}
Thanks in advance