at java.lang.Thread.run(Thread.java:835) [?:?]
[2019-10-17T15:01:11,672][DEBUG][o.e.a.s.TransportSearchAction] [wazuh-server] [auditbeat-7.4.0-2019.10.17][0], node[NkS_CcqmQbighUX_OrjIFw], [P], s[STARTED], a[id=JTHEi8YISVqs7j1AlxUGAQ]: Failed to execute [SearchRequest{searchType=QUERY_THEN_FETCH, indices=[auditbeat-*, filebeat-*, packetbeat-*, winlogbeat-*], indicesOptions=IndicesOptions[ignore_unavailable=true, allow_no_indices=true, expand_wildcards_open=true, expand_wildcards_closed=false, allow_aliases_to_multiple_indices=true, forbid_closed_indices=true, ignore_aliases=false, ignore_throttled=true], types=[], routing='null', preference='null', requestCache=null, scroll=null, maxConcurrentShardRequests=0, batchedReduceSize=512, preFilterShardSize=128, allowPartialSearchResults=true, localClusterAlias=null, getOrCreateAbsoluteStartMillis=-1, ccsMinimizeRoundtrips=true, source={"size":0,"query":{"bool":{"filter":[{"range":{"@timestamp":{"from":1571225273197,"to":1571311673197,"include_lower":true,"include_upper":true,"boost":1.0}}}],"should":[{"bool":{"must":[{"term":{"agent.type":{"value":"auditbeat","boost":1.0}}},{"term":{"event.module":{"value":"auditd","boost":1.0}}},{"term":{"event.action":{"value":"executed","boost":1.0}}}],"adjust_pure_negative":true,"boost":1.0}},{"bool":{"must":[{"term":{"agent.type":{"value":"auditbeat","boost":1.0}}},{"term":{"event.module":{"value":"system","boost":1.0}}},{"term":{"event.dataset":{"value":"process","boost":1.0}}}],"adjust_pure_negative":true,"boost":1.0}},{"bool":{"must":[{"term":{"agent.type":{"value":"winlogbeat","boost":1.0}}},{"term":{"event.code":{"value":"4688","boost":1.0}}}],"adjust_pure_negative":true,"boost":1.0}},{"bool":{"must":[{"term":{"winlog.event_id":{"value":1,"boost":1.0}}},{"term":{"winlog.channel":{"value":"Microsoft-Windows-Sysmon/Operational","boost":1.0}}}],"adjust_pure_negative":true,"boost":1.0}}],"adjust_pure_negative":true,"minimum_should_match":"1","boost":1.0}},"track_total_hits":-1,"aggregations":{"process_count":{"cardinality":{"field":"
process.name"}},"group_by_process":{"terms":{"field":"
process.name","size":11,"min_doc_count":1,"shard_min_doc_count":0,"show_term_doc_count_error":false,"order":[{"host_count":"asc"},{"_count":"asc"},{"_key":"asc"}]},"aggregations":{"process":{"top_hits":{"from":0,"size":1,"version":false,"seq_no_primary_term":false,"explain":false,"_source":{"includes":["process.args","
process.name","
user.id","
user.name"],"excludes":[]},"sort":[{"@timestamp":{"order":"desc"}}]}},"host_count":{"cardinality":{"field":"
host.name"}},"hosts":{"terms":{"field":"
host.name","size":10,"min_doc_count":1,"shard_min_doc_count":0,"show_term_doc_count_error":false,"order":[{"_count":"desc"},{"_key":"asc"}]},"aggregations":{"host":{"top_hits":{"from":0,"size":1,"version":false,"seq_no_primary_term":false,"explain":false,"_source":{"includes":[],"excludes":[]}}}}}}}}}}] lastShard [true]
org.elasticsearch.transport.RemoteTransportException: [wazuh-server][127.0.0.1:9300][indices:data/read/search[phase/query]]
Caused by: java.lang.IllegalArgumentException: Fielddata is disabled on text fields by default. Set fielddata=true on [
process.name] in order to load fielddata in memory by uninverting the inverted index. Note that this can however use significant memory. Alternatively use a keyword field instead.
at org.elasticsearch.index.mapper.TextFieldMapper$TextFieldType.fielddataBuilder(TextFieldMapper.java:759) ~[elasticsearch-7.3.2.jar:7.3.2]
at org.elasticsearch.index.fielddata.IndexFieldDataService.getForField(IndexFieldDataService.java:116) ~[elasticsearch-7.3.2.jar:7.3.2]
at org.elasticsearch.index.query.QueryShardContext.getForField(QueryShardContext.java:191) ~[elasticsearch-7.3.2.jar:7.3.2]
at org.elasticsearch.search.aggregations.support.ValuesSourceConfig.resolve(ValuesSourceConfig.java:95) ~[elasticsearch-7.3.2.jar:7.3.2]
at org.elasticsearch.search.aggregations.support.ValuesSourceAggregationBuilder.resolveConfig(ValuesSourceAggregationBuilder.java:321) ~[elasticsearch-7.3.2.jar:7.3.2]
at org.elasticsearch.search.aggregations.support.ValuesSourceAggregationBuilder.doBuild(ValuesSourceAggregationBuilder.java:314) ~[elasticsearch-7.3.2.jar:7.3.2]
at org.elasticsearch.search.aggregations.support.ValuesSourceAggregationBuilder$LeafOnly.doBuild(ValuesSourceAggregationBuilder.java:42) ~[elasticsearch-7.3.2.jar:7.3.2]
at org.elasticsearch.search.aggregations.AbstractAggregationBuilder.build(AbstractAggregationBuilder.java:139) ~[elasticsearch-7.3.2.jar:7.3.2]
at org.elasticsearch.search.aggregations.AggregatorFactories$Builder.build(AggregatorFactories.java:332) ~[elasticsearch-7.3.2.jar:7.3.2]
at org.elasticsearch.search.SearchService.parseSource(SearchService.java:789) ~[elasticsearch-7.3.2.jar:7.3.2]
at org.elasticsearch.search.SearchService.createContext(SearchService.java:591) ~[elasticsearch-7.3.2.jar:7.3.2]
at org.elasticsearch.search.SearchService.createAndPutContext(SearchService.java:550) ~[elasticsearch-7.3.2.jar:7.3.2]
at org.elasticsearch.search.SearchService.executeQueryPhase(SearchService.java:353) ~[elasticsearch-7.3.2.jar:7.3.2]
at org.elasticsearch.search.SearchService.lambda$executeQueryPhase$1(SearchService.java:340) ~[elasticsearch-7.3.2.jar:7.3.2]
at org.elasticsearch.action.ActionListener.lambda$map$2(ActionListener.java:145) ~[elasticsearch-7.3.2.jar:7.3.2]
at org.elasticsearch.action.ActionListener$1.onResponse(ActionListener.java:62) [elasticsearch-7.3.2.jar:7.3.2]
at org.elasticsearch.search.SearchService$2.doRun(SearchService.java:1052) [elasticsearch-7.3.2.jar:7.3.2]
at org.elasticsearch.common.util.concurrent.AbstractRunnable.run(AbstractRunnable.java:37) [elasticsearch-7.3.2.jar:7.3.2]
at org.elasticsearch.common.util.concurrent.TimedRunnable.doRun(TimedRunnable.java:44) [elasticsearch-7.3.2.jar:7.3.2]
at org.elasticsearch.common.util.concurrent.ThreadContext$ContextPreservingAbstractRunnable.doRun(ThreadContext.java:758) [elasticsearch-7.3.2.jar:7.3.2]
at org.elasticsearch.common.util.concurrent.AbstractRunnable.run(AbstractRunnable.java:37) [elasticsearch-7.3.2.jar:7.3.2]
at java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1128) [?:?]
at java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:628) [?:?]
at java.lang.Thread.run(Thread.java:835) [?:?]
[2019-10-17T15:15:00,775][INFO ][o.e.c.m.MetaDataUpdateSettingsService] [wazuh-server] updating number_of_replicas to [0] for indices [wazuh-monitoring-3.x-2019.10.17]
[2019-10-17T15:30:01,246][INFO ][o.e.c.m.MetaDataUpdateSettingsService] [wazuh-server] updating number_of_replicas to [0] for indices [wazuh-monitoring-3.x-2019.10.17]
[2019-10-17T15:45:01,671][INFO ][o.e.c.m.MetaDataUpdateSettingsService] [wazuh-server] updating number_of_replicas to [0] for indices [wazuh-monitoring-3.x-2019.10.17]
[2019-10-17T16:00:01,219][INFO ][o.e.c.m.MetaDataUpdateSettingsService] [wazuh-server] updating number_of_replicas to [0] for indices [wazuh-monitoring-3.x-2019.10.17]
[2019-10-17T16:15:01,627][INFO ][o.e.c.m.MetaDataUpdateSettingsService] [wazuh-server] updating number_of_replicas to [0] for indices [wazuh-monitoring-3.x-2019.10.17]
[2019-10-17T16:30:01,201][INFO ][o.e.c.m.MetaDataUpdateSettingsService] [wazuh-server] updating number_of_replicas to [0] for indices [wazuh-monitoring-3.x-2019.10.17]
[2019-10-17T16:45:01,565][INFO ][o.e.c.m.MetaDataUpdateSettingsService] [wazuh-server] updating number_of_replicas to [0] for indices [wazuh-monitoring-3.x-2019.10.17]
[2019-10-17T17:00:01,375][INFO ][o.e.c.m.MetaDataUpdateSettingsService] [wazuh-server] updating number_of_replicas to [0] for indices [wazuh-monitoring-3.x-2019.10.17]
[2019-10-17T17:15:01,657][INFO ][o.e.c.m.MetaDataUpdateSettingsService] [wazuh-server] updating number_of_replicas to [0] for indices [wazuh-monitoring-3.x-2019.10.17]
[2019-10-17T17:30:01,080][INFO ][o.e.c.m.MetaDataUpdateSettingsService] [wazuh-server] updating number_of_replicas to [0] for indices [wazuh-monitoring-3.x-2019.10.17]
[2019-10-17T17:45:01,634][INFO ][o.e.c.m.MetaDataUpdateSettingsService] [wazuh-server] updat
curl
http://localhost:9200/_cat/templates.monitoring-alerts-7 [.monitoring-alerts-7] 0 7000199
.ml-state [.ml-state*] 0 7030299
wazuh-agent [wazuh-monitoring-3.x-*] 0
logstash [logstash-*] 0 60001
auditbeat-7.4.0 [auditbeat-7.4.0-*] 1
.monitoring-beats [.monitoring-beats-7-*] 0 7000199
.ml-meta [.ml-meta] 0 7030299
.watch-history-10 [.watcher-history-10*]
2147483647 .management-beats [.management-beats] 0 70000
.triggered_watches [.triggered_watches*]
2147483647 .logstash-management [.logstash] 0
.watches [.watches*]
2147483647 .monitoring-logstash [.monitoring-logstash-7-*] 0 7000199
filebeat-7.3.2 [filebeat-7.3.2-*] 1
wazuh [wazuh-alerts-3.x-*, wazuh-archives-3.x-*] 0 1
.monitoring-es [.monitoring-es-7-*] 0 7000199
.kibana_task_manager [.kibana_task_manager] 0 7030299
.data-frame-notifications-1 [.data-frame-notifications-*] 0 7030299
.ml-notifications [.ml-notifications] 0 7030299
.monitoring-kibana [.monitoring-kibana-7-*] 0 7000199
.ml-anomalies- [.ml-anomalies-*] 0 7030299
.data-frame-internal-1 [.data-frame-internal-1] 0 7030299
.ml-config [.ml-config] 0 7030299