Indicator Match detection rules using Value Lists not working in 8.6.0

Hello, when I create an Indicator Match detection rule using an uploaded value list (following instructions from Create a detection rule | Elastic Security Solution [8.6] | Elastic), the rule fails to execute with the following error:

An error occurred during rule execution: message: "search_phase_execution_exception: [query_shard_exception] Reason: No mapping found for [@timestamp] in order to sort on"

The Data View I am searching on does have a @timestamp field, but I noticed that the .items-* indices do not. I believe these rules worked for me without issue in version 8.5.0.

Hey, can you share your rule configuration?

One possible error can be if you use .items-* instead of .items-${spaceName} (.items-default for example)

1 Like

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.