So the cluster has been running for about 2 months no issues or changes. Recently within the past 5 days:
Bulk Indexing of signals failed: reason: "No mapping found for [@timestamp] in order to sort on" type: "query_shard_exception" name: "RPC (Remote Procedure Call) from the Internet" id: "d47c9279-89e9-489e-b626-639f12103f0b" rule id: "143cb236-0956-4f42-a706-814bcaa0cf5a" signals index: ".siem-signals-default"
On about 60+ rules.
I haven't had the time to go back and figure out why this happened. Anyone have a pointer it looks easy to fix as it's missing a mapping but not sure on the safest course of action would be at this point.