Check WAZUH alert index pattern warning

546 views
Skip to first unread message

SaiRajan Puratchivel

unread,
Sep 28, 2022, 6:36:40 AM9/28/22
to Wazuh mailing list
Hello,

We have installed the Wazuh 4.3 version.  While opening the browser version getting the attached error.  

Checked the Filbeat where elastic search is properly configured and working.

elasticsearch:

  parse url... OK

  connection...

    parse host... OK

    dns lookup... OK

    addresses: 

    dial up... OK


Thanks,

Sai

Screenshot 2022-09-28 at 16.05.39.png

Kasim Mustapha

unread,
Sep 28, 2022, 7:08:31 AM9/28/22
to Wazuh mailing list
Hello Sairajan,

Thanks for reaching out.

Could you check the templates?
Using Kibana Dev Tools: GET _cat/templates

On the other hand, to remove old indices could you do with this guide or if you want to keep your old indices you could reindex them with this guide and I recommend using Dev Tools for safety.

Await your response.

Regards.

SaiRajan Puratchivel

unread,
Sep 28, 2022, 7:39:04 AM9/28/22
to Wazuh mailing list
Hi Kasim,

Thanks for responding back.

When I tried to run the GET _cat/templates I am getting 2 responses in the DEV Tools console.

I have attached the screenshot for your reference.

Thanks,
Sai
Screenshot 2022-09-28 at 17.04.34.png

Kasim Mustapha

unread,
Sep 28, 2022, 8:17:09 AM9/28/22
to Wazuh mailing list
Hello Sairajan,

We noticed that the alert index pattern is not available. Elasticsearch needs a specific template to store Wazuh alerts, otherwise, visualizations won't load properly. 


For more information check out the documentation here: https://documentation.wazuh.com/current/user-manual/elasticsearch/configure-indices.html

Hope this helps. Let us know if you have further questions.
Regards,

SaiRajan Puratchivel

unread,
Sep 28, 2022, 10:51:05 AM9/28/22
to Wazuh mailing list
Hi Kasim,


FYI: In this document I see no.6 is optional but after doing that step only my issue got fixed.

Thank you for your assistance and prompt turnaround.

Regards,
Sai
Reply all
Reply to author
Forward
0 new messages