Alert rule for standard cluster alerts: search_phase_execution_exception [illegal_argument_exception]

7.14.1
Platinum license

Setting up brand new cluster, and have configured metricbeat style monitoring of cluster (separate elasticsearch for monitoring).

Entered setup mode and did the add of standard alerts. Looks like these rules got created but am seeing Error status on all.

  • CCR read exceptions
  • CPU Usage
  • Cluster health
  • Disk Usage
  • Elasticsearch version mismatch
  • Kibana version mismatch
  • License expiration
  • Memory Usage (JVM)

Error that is shown for each....

search_phase_execution_exception: [illegal_argument_exception] Reason: no mapping found for cluster_uuid in order to collapse on; [illegal_argument_exception]