Hi,
I'm running the 7.9.2 version of the stack in a hot-warm cluster architecture.
When defining a very simple detection rule on my space called "siem" I get the following error intermittently. One execution succeed and one fails with:
{"type":"log","@timestamp":"2020-10-21T14:16:06Z","tags":["error","plugins","securitySolution","plugins","securitySolution"],"pid":6587,"message":"[-] search_after and bulk threw an error TypeError: Cannot read property 'some' of undefined name: \"Rogue AP Detection\" id: \"376e5caf-7fa0-4657-87b5-33ee249f9b3b\" rule id: \"b57a7041-d90f-4023-adf4-09e19182dcea\" signals index: \".siem-signals-siem\""}
{"type":"log","@timestamp":"2020-10-21T14:16:06Z","tags":["error","plugins","securitySolution","plugins","securitySolution"],"pid":6587,"message":"Bulk Indexing of signals failed. Check logs for further details. name: \"Rogue AP Detection\" id: \"376e5caf-7fa0-4657-87b5-33ee249f9b3b\" rule id: \"b57a7041-d90f-4023-adf4-09e19182dcea\" signals index: \".siem-signals-siem\""}
{"type":"log","@timestamp":"2020-10-21T14:36:18Z","tags":["error","plugins","securitySolution","plugins","securitySolution"],"pid":6587,"message":"[-] search_after and bulk threw an error TypeError: Cannot read property 'some' of undefined name: \"Rogue AP Detection\" id: \"376e5caf-7fa0-4657-87b5-33ee249f9b3b\" rule id: \"b57a7041-d90f-4023-adf4-09e19182dcea\" signals index: \".siem-signals-siem\""}
{"type":"log","@timestamp":"2020-10-21T14:36:18Z","tags":["error","plugins","securitySolution","plugins","securitySolution"],"pid":6587,"message":"Bulk Indexing of signals failed. Check logs for further details. name: \"Rogue AP Detection\" id: \"376e5caf-7fa0-4657-87b5-33ee249f9b3b\" rule id: \"b57a7041-d90f-4023-adf4-09e19182dcea\" signals index: \".siem-signals-siem\""}
Thank you
Regards
Ana