Hi @leandrojmp; @nickpeihl ,
here are the patterns using GET /_template/siem_alarms-*
{
"siem_alarms-*" : {
"order" : 0,
"version" : 1,
"index_patterns" : [
"siem_alarms-*"
],
"settings" : {
"index" : {
"number_of_shards" : "1",
"number_of_replicas" : "0",
"refresh_interval" : "1s"
}
},
"mappings" : {
"dynamic_templates" : [
{
"string_as_keywords" : {
"mapping" : {
"norms" : false,
"type" : "text",
"fields" : {
"keyword" : {
"ignore_above" : 256,
"type" : "keyword"
}
}
},
"match_mapping_type" : "string"
}
}
],
"properties" : {
"src_ips" : {
"type" : "ip"
},
"dst_ips" : {
"type" : "ip"
}
}
},
"aliases" : {
"siem_alarms" : { },
"siem_alarms_id_lookup" : { }
}
}
}
GET /_template/siem_alarms
{
"siem_alarms" : {
"order" : 0,
"version" : 1,
"index_patterns" : [
"siem_alarms-*"
],
"settings" : {
"index" : {
"number_of_shards" : "1",
"number_of_replicas" : "0",
"refresh_interval" : "1s"
}
},
"mappings" : {
"dynamic_templates" : [
{
"strings_as_keywords" : {
"mapping" : {
"norms" : false,
"type" : "text",
"fields" : {
"keyword" : {
"ignore_above" : 256,
"type" : "keyword"
}
}
},
"match_mapping_type" : "string"
}
}
],
"properties" : {
"src_ips" : {
"type" : "ip"
},
"dst_ips" : {
"type" : "ip"
}
}
},
"aliases" : {
"siem_alarms" : { },
"siem_alarms_id_lookup" : { }
}
}
}
GET /_template/siem_alarm_events
{
"siem_alarm_events" : {
"order" : 0,
"version" : 1,
"index_patterns" : [
"siem_alarm_events-*"
],
"settings" : {
"index" : {
"number_of_shards" : "1",
"number_of_replicas" : "0",
"refresh_interval" : "1s"
}
},
"mappings" : {
"dynamic_templates" : [
{
"strings_as_keywords" : {
"mapping" : {
"norms" : false,
"type" : "text",
"fields" : {
"keyword" : {
"ignore_above" : 256,
"type" : "keyword"
}
}
},
"match_mapping_type" : "string"
}
}
]
},
"aliases" : { }
}
}
However I can see index patterns GET /_template/siem_alarms-*
and GET /_template/siem_alarms
could that be the cause of the problem because I only need one