# Error fetching fields for data in Security Dashboard

**URL:** <https://discuss.elastic.co/t/error-fetching-fields-for-data-in-security-dashboard/313573>\
**Category:** Kibana\
**Tags:** elastic-stack-security\
**Created:** [September 2, 2022, 5:23pm UTC](https://discuss.elastic.co/t/error-fetching-fields-for-data-in-security-dashboard/313573 "2022-09-02T17:23:34Z")\
**Posts on this page:** 15\
**Page:** 1

<div class="post-metadata">

**Author:** ![GustavoPires](https://avatars.discourse-cdn.com/v4/letter/g/13edae/32.png) [@GustavoPires](https://discuss.elastic.co/u/GustavoPires)\
**Post date:** [September 2, 2022, 5:23pm UTC](https://discuss.elastic.co/t/error-fetching-fields-for-data-in-security-dashboard/313573/1 "2022-09-02T17:23:34Z")

</div>

Hello guys, I am getting the error below when I go to the security dashboard overview:

> Error fetching fields for data view .alerts-security.alerts-default,apm-_-transaction_,auditbeat-_,endgame-_,filebeat-_,logs-_,packetbeat-_,traces-apm_,winlogbeat-\*,-_elastic-cloud-logs-_ (ID: security-solution-default)

When I look at: **stack management \> Kibana \> Advanced Settings \> Security Solution \> Elasticsearch indices** , I only have these indices:

> _apm--transaction, auditbeat-, endgame-, filebeat-, logs-, packetbeat-, traces-apm, winlogbeat-\*, -elastic-cloud-logs-_

If I change (for example, I was trying to include **.alerts-security.alerts-default** ), the error persists, and I don't have this index in my cluster, what can I do to fix this? All my rules in SIEM are getting this error too (I believe is because of the index).

**Kibana logs:**

> "message":"Changing rule status to "partial failure". This rule is attempting to query data from Elasticsearch indices listed in the "Index pattern" section of the rule definition, however no index matching: ["logs-endpoint.alerts-\*"] was found. This warning will continue to appear until a matching index is created or this rule is disabled. If you have recently enrolled agents enabled with Endpoint Security through Fleet, this warning should stop once an alert is sent from an agent.

---

<div class="post-metadata">

**Author:** ![stephmilovic](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephmilovic/32/146835_2.png) [@stephmilovic](https://discuss.elastic.co/u/stephmilovic)\
**Post date:** [September 13, 2022, 6:37pm UTC](https://discuss.elastic.co/t/error-fetching-fields-for-data-in-security-dashboard/313573/2 "2022-09-13T18:37:40Z")

</div>

Hi @GustavoPires, apologies for the delay in response. If you are running rules, you should have the index `.alerts-security.alerts-default`. It only gets added to the security solution data view if it exists, whether or not it is included in the **stack management \> Kibana \> Advanced Settings \> Security Solution \> Elasticsearch indices**. So this tells me maybe your rules aren't running, or if they are they are not detecting any alerts to write to the index. Could you please ensure you have the index and/or that your rules are creating alerts?

---

<div class="post-metadata">

**Author:** ![GustavoPires](https://avatars.discourse-cdn.com/v4/letter/g/13edae/32.png) [@GustavoPires](https://discuss.elastic.co/u/GustavoPires)\
**Post date:** [September 14, 2022, 2:25pm UTC](https://discuss.elastic.co/t/error-fetching-fields-for-data-in-security-dashboard/313573/3 "2022-09-14T14:25:13Z")

</div>

Hi @stephmilovic, I have added this index to my Elasticsearch indices, but this error persists, for the test, I have enabled all rules of Elastic, but, without alerts.

---

<div class="post-metadata">

**Author:** ![stephmilovic](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephmilovic/32/146835_2.png) [@stephmilovic](https://discuss.elastic.co/u/stephmilovic)\
**Post date:** [September 14, 2022, 3:08pm UTC](https://discuss.elastic.co/t/error-fetching-fields-for-data-in-security-dashboard/313573/4 "2022-09-14T15:08:52Z")

</div>

I think creating the index yourself vs having the SIEM create it may be the problem. Go ahead and delete the index. Then create and run a rule that detects on something simple that will for sure trigger an alert, for example `host.name:*`. Let's get some alerts going

---

<div class="post-metadata">

**Author:** ![GustavoPires](https://avatars.discourse-cdn.com/v4/letter/g/13edae/32.png) [@GustavoPires](https://discuss.elastic.co/u/GustavoPires)\
**Post date:** [September 16, 2022, 6:43pm UTC](https://discuss.elastic.co/t/error-fetching-fields-for-data-in-security-dashboard/313573/5 "2022-09-16T18:43:52Z")

</div>

@stephmilovic I searched for `.alerts-security.alerts-default` on dev tools, but I only have this index: `.internal.alerts-security.alerts-default-000001`. I tried creating with **PUT** the index `.alerts-security.alerts-default` but appear this message: "this index already exists". So If I delete the index `.alerts-security.alerts-default`, do I need to recreate them, right?

**Observation:** _I recreate a new environment with Elasticsearch, and the same message ("...Error fetching fields for data view...") appears. My SIEM rules are OK now, but when I access security dashboard the message persists._

---

<div class="post-metadata">

**Author:** ![stephmilovic](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephmilovic/32/146835_2.png) [@stephmilovic](https://discuss.elastic.co/u/stephmilovic)\
**Post date:** [September 19, 2022, 6:42pm UTC](https://discuss.elastic.co/t/error-fetching-fields-for-data-in-security-dashboard/313573/6 "2022-09-19T18:42:40Z")

</div>

you should not manually create the `.alerts-security.alerts-default`, it gets created automatically when a rule detects an alert for the first time.

Can you post a screenshot of the error?

---

<div class="post-metadata">

**Author:** ![GustavoPires](https://avatars.discourse-cdn.com/v4/letter/g/13edae/32.png) [@GustavoPires](https://discuss.elastic.co/u/GustavoPires)\
**Post date:** [September 19, 2022, 6:51pm UTC](https://discuss.elastic.co/t/error-fetching-fields-for-data-in-security-dashboard/313573/7 "2022-09-19T18:51:56Z")

</div>

It's the third/fourth time I've installed the elastic stack environment and it gives this error 😔.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/d/9/d909d5f07c390e63b0c35a526aeb607c27671bb9.png)

Every time I refresh the page this error appears.

---

<div class="post-metadata">

**Author:** ![yctercero](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yctercero/32/68560_2.png) [@yctercero](https://discuss.elastic.co/u/yctercero)\
**Post date:** [September 20, 2022, 12:51am UTC](https://discuss.elastic.co/t/error-fetching-fields-for-data-in-security-dashboard/313573/8 "2022-09-20T00:51:29Z")

</div>

Hi @GustavoPires !

What version of Kibana are you on?

Like @stephmilovic mentioned - the alerts index is create automatically when the very first alert is created. The `.internal.alerts-security` is the concrete index, and `.alerts-security` is the alias used. But like Steph said - these are internally managed indices. Trying to create them on your own can definitely cause issues as it may not pick up the right template, etc.

Are all the rules you currently have using data views or are any using index patterns? If you go to rule details you will see that it either says `Index pattern: ...` or `Data view: ...`. If you could create a rule that specifies an index you know has data you can hit with a very generic query to try to generate an alert like Steph suggested, that should create the alerts index and then maybe this data view error will stop.

Please let me know if that works!

---

<div class="post-metadata">

**Author:** ![GustavoPires](https://avatars.discourse-cdn.com/v4/letter/g/13edae/32.png) [@GustavoPires](https://discuss.elastic.co/u/GustavoPires)\
**Post date:** [September 20, 2022, 5:08pm UTC](https://discuss.elastic.co/t/error-fetching-fields-for-data-in-security-dashboard/313573/9 "2022-09-20T17:08:33Z")

</div>

Hi @yctercero, I believe is 8.4.1, when I go to Stack Management is 8.4.1 there, and I installed it via apt (Ubuntu Server).

> [@yctercero](#):
>
> Like @stephmilovic mentioned - the alerts index is create automatically when the very first alert is created. The `.internal.alerts-security` is the concrete index, and `.alerts-security` is the alias used. But like Steph said - these are internally managed indices. Trying to create them on your own can definitely cause issues as it may not pick up the right template, etc.

Ok, understood, I won't try to create an index again, because of this I reinstalled all my Elastic Stack environments.

> [@yctercero](#):
>
> Are all the rules you currently have using data views or are any using index patterns? If you go to rule details you will see that it either says `Index pattern: ...` or `Data view: ...`.

I am using prebuilt rules of the Elastic Stack, with these tags: APM, Endpoint Security, and Linux. When I go to the top of the rule (while I am editing the rules), precisely at "Definition", I can see "Index patterns" at these rules.

> [@yctercero](#):
>
> If you could create a rule that specifies an index you know has data you can hit with a very generic query to try to generate an alert like Steph suggested, that should create the alerts index and then maybe this data view error will stop.

Ok, so I created two rules for querying a name host (`host.name:`, like @stephmilovic said), using the data view and index patterns. The rule is working, I can get the name of my machine through these two queries, but the error persists. When I created a rule using index pattern, I did not see `.alerts-security.alerts-default `, do I have to put it there?

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/0/5/058324d1ae2af89370060d16ed44dc587f147823.png)

---

<div class="post-metadata">

**Author:** ![stephmilovic](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephmilovic/32/146835_2.png) [@stephmilovic](https://discuss.elastic.co/u/stephmilovic)\
**Post date:** [September 20, 2022, 6:39pm UTC](https://discuss.elastic.co/t/error-fetching-fields-for-data-in-security-dashboard/313573/10 "2022-09-20T18:39:02Z")

</div>

> [@GustavoPires](#):
>
> When I created a rule using index pattern, I did not see `.alerts-security.alerts-default `, do I have to put it there?

Unless you want to be alerting on alert events, you do **not** want the alerts index selected here. This could result in redundant alerts being generated from existing alerts.

Do you get the same error when you go to **Stack Management \> Kibana \> Data Views** and click into the security data view? The url: `http://your:instance/app/management/kibana/dataViews/dataView/security-solution-default#/?_a=(tab:indexedFields)`

What happens when you get that error and click "See the full error", can you please screenshot that?

---

<div class="post-metadata">

**Author:** ![GustavoPires](https://avatars.discourse-cdn.com/v4/letter/g/13edae/32.png) [@GustavoPires](https://discuss.elastic.co/u/GustavoPires)\
**Post date:** [September 20, 2022, 6:48pm UTC](https://discuss.elastic.co/t/error-fetching-fields-for-data-in-security-dashboard/313573/11 "2022-09-20T18:48:56Z")

</div>

> [@stephmilovic](#):
>
> Do you get the same error when you go to **Stack Management \> Kibana \> Data Views** and click into the security data view? The url:

Yes, I am getting this message here too.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/6/f/6fc093df2257e10abb4ecc7c81cdee643f2ed24a.png)

"See the full error" bellow:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/1/3/135a8cc9a1a60445b1746a04d9bcfef689845869.png)

---

<div class="post-metadata">

**Author:** ![stephmilovic](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephmilovic/32/146835_2.png) [@stephmilovic](https://discuss.elastic.co/u/stephmilovic)\
**Post date:** [September 20, 2022, 10:05pm UTC](https://discuss.elastic.co/t/error-fetching-fields-for-data-in-security-dashboard/313573/12 "2022-09-20T22:05:43Z")

</div>

Ok here is a debugging idea. From the Security Data View Details view, (again `http://your:instance/app/management/kibana/dataViews/dataView/security-solution-default#/?_a=(tab:indexedFields)`), please hit the "Edit" button.

 ![Screen Shot 2022-09-20 at 4.59.17 PM](https://us1.discourse-cdn.com/elastic/original/3X/7/2/72f2a03d0ce3d0e58c895fabf8eb6e77becaea5c.jpeg)

From the "Index Pattern" field, remove an index alias one at a time, press "Save" and see if the error persists on that page. For example:

1. `.alerts-security.alerts-default,apm-*-transaction* ,auditbeat-*,endgame-* ,filebeat-*,logs-* ,packetbeat-*,traces-apm* ,winlogbeat-*,-*elastic-cloud-logs-*`
2. `apm-*-transaction* ,auditbeat-*,endgame-* ,filebeat-*,logs-* ,packetbeat-*,traces-apm* ,winlogbeat-*,-*elastic-cloud-logs-*`
3. `auditbeat-*,endgame-* ,filebeat-*,logs-* ,packetbeat-*,traces-apm* ,winlogbeat-*,-*elastic-cloud-logs-*`
4. `endgame-* ,filebeat-*,logs-* ,packetbeat-*,traces-apm* ,winlogbeat-*,-*elastic-cloud-logs-*`
5. `filebeat-*,logs-* ,packetbeat-*,traces-apm* ,winlogbeat-*,-*elastic-cloud-logs-*`
6. `logs-* ,packetbeat-*,traces-apm* ,winlogbeat-*,-*elastic-cloud-logs-*`

My goal is to narrow down which index the error is coming from. I'm asking the team for help with what to do with the field error once we identify the index

EDIT: Do not navigate to the Security Solution during this exercise as this will reset the index pattern

---

<div class="post-metadata">

**Author:** ![stephmilovic](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephmilovic/32/146835_2.png) [@stephmilovic](https://discuss.elastic.co/u/stephmilovic)\
**Post date:** [September 20, 2022, 11:37pm UTC](https://discuss.elastic.co/t/error-fetching-fields-for-data-in-security-dashboard/313573/13 "2022-09-20T23:37:45Z")

</div>

Could you also please provide a har file? [Kibana HAR Instructions · GitHub](https://gist.github.com/legrego/7154b71096a09876423e2bd61d6a3e0f)

---

<div class="post-metadata">

**Author:** ![GustavoPires](https://avatars.discourse-cdn.com/v4/letter/g/13edae/32.png) [@GustavoPires](https://discuss.elastic.co/u/GustavoPires)\
**Post date:** [September 22, 2022, 1:12pm UTC](https://discuss.elastic.co/t/error-fetching-fields-for-data-in-security-dashboard/313573/14 "2022-09-22T13:12:16Z")

</div>

At Dataview I'm trying to edit but it's not saving (I save the edit, but nothing changes on the `Index pattern`). Do I have to perform a specific action to do the HAR file?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 20, 2022, 1:12pm UTC](https://discuss.elastic.co/t/error-fetching-fields-for-data-in-security-dashboard/313573/15 "2022-10-20T13:12:47Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
