Hey there @aditi_salunke
This appears similar to Detection Custom Rule not working, however you're also experiencing it on the Stack Monitoring page it looks like? Are you seeing this error anywhere else by chance?
Also noted that this occurs when using a user with the superuser
role -- can you share the current user's role definition, and any configured document level security options that may be present? Similar type errors can bubble up from ES when there's something wrong with those configurations.
In addition, can you verify the following?
- What version and type of deployment are you on?
- Did this start happening after a specific configuration change, or addition of new rules? If so, can you provide more details as to what changes, or the rules in question?
Thanks!
Garrett