Skip to content

ES Could not index events after update from RC3 #1547

Locked Answered by TOoSmOotH
shipler asked this question in Q&A
Discussion options

You must be logged in to vote

We made some changes to the ECS schema from RC3 to GA. You should be able to index new data once the index rolls over to the next day. https://docs.securityonion.net/en/2.3/release-notes.html explain it in more detail.

Replies: 1 comment

Comment options

You must be logged in to vote
0 replies
Answer selected by dougburks
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants
Converted from issue

This discussion was converted from issue #1547 on October 19, 2020 11:51.