[Osquery] Live Queries in Osquery do not display results, show "pending" then "expired" #183142
Labels
bug
Fixes for quality problems that affect the customer experience
Team:Defend Workflows
“EDR Workflows” sub-team of Security Solution
Kibana version: 8.12.2
Elasticsearch version: 8.12.2
Original install method (e.g. download page, yum, from source, etc.): Docker
**Describe the bug: **
The data returned by osquery is not displayed in Live Queries. Osquery shows a status of "pending" and then "expired", even though the agent returns a response because I can find it in the index ".ds-logs-osquery_manager.result". You can view it by clicking "View in Discover".
Steps to reproduce:
Screenshots (if relevant):
logs:
[2024-05-08T09:57:14.870+02:00][WARN ][plugins.fleet] large amount of default fields detected for index template logs-osquery_manager.result in package osquery_manager, applying the first 1024 fields
[2024-05-08T09:57:28.623+02:00][INFO ][plugins.fleet] Attempt to update the mappings for the logs-osquery_manager.result-abs (write_index_only)
[2024-05-08T09:57:28.631+02:00][INFO ][plugins.fleet] Attempt to update the mappings for the logs-osquery_manager.result-default (write_index_only)
[2024-05-08T09:57:28.730+02:00][INFO ][plugins.fleet] Mappings update for logs-osquery_manager.result-abs failed due to ResponseError: illegal_argument_exception
[2024-05-08T09:57:28.730+02:00][INFO ][plugins.fleet] Triggering a rollover for logs-osquery_manager.result-abs
[2024-05-08T09:57:28.830+02:00][INFO ][plugins.fleet] Mappings update for logs-osquery_manager.result-default failed due to ResponseError: illegal_argument_exception
[2024-05-08T09:57:28.830+02:00][INFO ][plugins.fleet] Triggering a rollover for logs-osquery_manager.result-default
[2024-05-08T09:57:42.950+02:00][ERROR][plugins.fleet] FleetError: error deleting pipeline logs-osquery_manager.result-1.8.4: ResponseError: illegal_argument_exception
illegal_argument_exception: pipeline [logs-osquery_manager.result-1.8.4] cannot be deleted because it is the default pipeline for 4 index(es) including [.ds-logs-osquery_manager.result-abs-2024.03.30-000054,.ds-logsosquery_manager.result-abs-2024.04.29-000056,.ds-logs-osquery_manager.result-default-2024.03.14-000002]
The text was updated successfully, but these errors were encountered: