Hi,
I'm following up on this post, as we're experiencing the exact same problem.
We can create a new post if needed.
We have three sites: one with an indexer on each site, and the main site with the dashboard.
Each site has an index pattern.
For one site, we're getting this message in the "Vulnerability Detection" events. This doesn't occur in "Threat Hunting."
We've identified the log line: Dec. 09 10:30:54 SERVER1 opensearch-dashboards[337727]: {"type":"log","@timestamp":"2025-12-09T09:30:54Z","tags":["error","plugins","wazuh","POST /utils/logs/ui","ui"],"pid":337727,"message":"\n in G\n in div\n in s\n in div\n in EuiFlexGroup\n in div\n in Unknown\n in div\n in div\n in s\n in div\n in EuiFlexGroup\n in div\n in Unknown\n in div\n in Unknown\n in bJ\n in div\n in Unknown\n in div\n in Unknown\n in YJ\n in IntlProvider\n in withErrorBoundary(WazuhDiscoverComponent)\n in error_boundary_ErrorBoundary\n in Unknown\n in component\n in div\n in MainModuleOverview\n in Connect(MainModuleOverview)\n in withErrorBoundary(withErrorBoundary(withErrorBoundary(withErrorBoundary(withErrorBoundary(withErrorBoundary(MainModule))))))\n in error_boundary_ErrorBoundary\n in Unknown\n in Unknown\n in Unknown\n in t\n in t\n in t\n in Application\n in Provider\n in Ie\n in IntlProvider\n in Be: can't access property \"toLowerCase\" of undefined"}
This follows the deletion and creation of the patern index.
We had identified a format problem in the paternal index which was not good (such as string instead of a date format).
We're having trouble identifying and resolving the root cause of the problem.
Can you help us?
Thank you for your help.
PS: Translated from French to English using Google Translate