The query of the managed machine learning job packetbeat_rare_user_agent doesn't match with any documents. It seems like event.dataset is not in the logs-network_traffic.http-* datastream?
@willemdh your assessment looks accurate, here: some of our newer integrations are populating data_stream.dataset instead of the earlier event.dataset, and our ML Jobs have not been updated to capture those data.
The team has filed an issue to track/update the ML job queries, but your workaround should also suffice in the interim: changing either the query or the data should address the issue.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.