@Frank_Hassanabad Well, as I said currently things are working again:
today I check these rules again and seems they suddenly work again.. Afaik nothing has changed, no idea what's going on..
Checked our filebeat-* indices and I didn't notice any indices with different or missing timestamp mappings:
GET filebeat-*/_mapping/field/@timestamp
{
"filebeat-7.10.1-2020.12.31-000028" : {
"mappings" : {
"@timestamp" : {
"full_name" : "@timestamp",
"mapping" : {
"@timestamp" : {
"type" : "date"
}
}
}
}
},
"filebeat-7.10.1-2020.12.30-000026" : {
"mappings" : {
"@timestamp" : {
"full_name" : "@timestamp",
"mapping" : {
"@timestamp" : {
"type" : "date"
}
}
}
}
},
"filebeat-7.10.1-2020.12.31-000027" : {
"mappings" : {
"@timestamp" : {
"full_name" : "@timestamp",
"mapping" : {
"@timestamp" : {
"type" : "date"
}
}
}
}
},
"filebeat-7.10.2-2021.01.28-000007" : {
"mappings" : {
"@timestamp" : {
"full_name" : "@timestamp",
"mapping" : {
"@timestamp" : {
"type" : "date"
}
}
}
}
},
"filebeat-7.10.1-2021.01.01-000029" : {
"mappings" : {
"@timestamp" : {
"full_name" : "@timestamp",
"mapping" : {
"@timestamp" : {
"type" : "date"
}
}
}
}
},
"filebeat-7.10.2-2021.01.19-000001" : {
"mappings" : {
"@timestamp" : {
"full_name" : "@timestamp",
"mapping" : {
"@timestamp" : {
"type" : "date"
}
}
}
}
},
"filebeat-7.10.2-2021.01.21-000002" : {
"mappings" : {
"@timestamp" : {
"full_name" : "@timestamp",
"mapping" : {
"@timestamp" : {
"type" : "date"
}
}
}
}
},
"filebeat-7.10.2-2021.01.26-000006" : {
"mappings" : {
"@timestamp" : {
"full_name" : "@timestamp",
"mapping" : {
"@timestamp" : {
"type" : "date"
}
}
}
}
},
"filebeat-7.10.2-2021.01.25-000005" : {
"mappings" : {
"@timestamp" : {
"full_name" : "@timestamp",
"mapping" : {
"@timestamp" : {
"type" : "date"
}
}
}
}
},
"filebeat-7.10.2-2021.01.22-000003" : {
"mappings" : {
"@timestamp" : {
"full_name" : "@timestamp",
"mapping" : {
"@timestamp" : {
"type" : "date"
}
}
}
}
},
"filebeat-7.10.2-2021.01.24-000004" : {
"mappings" : {
"@timestamp" : {
"full_name" : "@timestamp",
"mapping" : {
"@timestamp" : {
"type" : "date"
}
}
}
}
},
"filebeat-7.10.1-2021.01.07-000036" : {
"mappings" : {
"@timestamp" : {
"full_name" : "@timestamp",
"mapping" : {
"@timestamp" : {
"type" : "date"
}
}
}
}
},
"filebeat-7.10.1-2021.01.08-000037" : {
"mappings" : {
"@timestamp" : {
"full_name" : "@timestamp",
"mapping" : {
"@timestamp" : {
"type" : "date"
}
}
}
}
},
"filebeat-7.10.1-2021.01.04-000034" : {
"mappings" : {
"@timestamp" : {
"full_name" : "@timestamp",
"mapping" : {
"@timestamp" : {
"type" : "date"
}
}
}
}
},
"filebeat-7.10.1-2021.01.05-000035" : {
"mappings" : {
"@timestamp" : {
"full_name" : "@timestamp",
"mapping" : {
"@timestamp" : {
"type" : "date"
}
}
}
}
},
"filebeat-7.10.1-2021.01.11-000039" : {
"mappings" : {
"@timestamp" : {
"full_name" : "@timestamp",
"mapping" : {
"@timestamp" : {
"type" : "date"
}
}
}
}
},
"filebeat-7.10.1-2021.01.10-000038" : {
"mappings" : {
"@timestamp" : {
"full_name" : "@timestamp",
"mapping" : {
"@timestamp" : {
"type" : "date"
}
}
}
}
},
"filebeat-7.10.1-2021.01.01-000030" : {
"mappings" : {
"@timestamp" : {
"full_name" : "@timestamp",
"mapping" : {
"@timestamp" : {
"type" : "date"
}
}
}
}
},
"filebeat-7.10.1-2021.01.02-000031" : {
"mappings" : {
"@timestamp" : {
"full_name" : "@timestamp",
"mapping" : {
"@timestamp" : {
"type" : "date"
}
}
}
}
},
"filebeat-7.10.1-2021.01.03-000033" : {
"mappings" : {
"@timestamp" : {
"full_name" : "@timestamp",
"mapping" : {
"@timestamp" : {
"type" : "date"
}
}
}
}
},
"filebeat-7.10.1-2021.01.03-000032" : {
"mappings" : {
"@timestamp" : {
"full_name" : "@timestamp",
"mapping" : {
"@timestamp" : {
"type" : "date"
}
}
}
}
},
"filebeat-7.10.1-2021.01.16-000042" : {
"mappings" : {
"@timestamp" : {
"full_name" : "@timestamp",
"mapping" : {
"@timestamp" : {
"type" : "date"
}
}
}
}
},
"filebeat-7.10.1-2021.01.13-000040" : {
"mappings" : {
"@timestamp" : {
"full_name" : "@timestamp",
"mapping" : {
"@timestamp" : {
"type" : "date"
}
}
}
}
},
"filebeat-7.10.1-2021.01.14-000041" : {
"mappings" : {
"@timestamp" : {
"full_name" : "@timestamp",
"mapping" : {
"@timestamp" : {
"type" : "date"
}
}
}
}
},
"filebeat-7.10.1-2021.01.17-000043" : {
"mappings" : {
"@timestamp" : {
"full_name" : "@timestamp",
"mapping" : {
"@timestamp" : {
"type" : "date"
}
}
}
}
},
"filebeat-7.10.1-2021.01.19-000044" : {
"mappings" : {
"@timestamp" : {
"full_name" : "@timestamp",
"mapping" : {
"@timestamp" : {
"type" : "date"
}
}
}
}
},
"filebeat-7.10.1-2020.12.30-000025" : {
"mappings" : {
"@timestamp" : {
"full_name" : "@timestamp",
"mapping" : {
"@timestamp" : {
"type" : "date"
}
}
}
}
}
}
Anyway, it works now, so let's assume it was a temporary glitch which might be prevented by the PR above.
Grtz
Willem