I check the OpenSearch logs but didn’t find anything that caught my eye, except for these entries:
[2023-01-31T10:06:44,764][INFO ][o.o.c.m.MetadataIndexTemplateService] [node-1] adding template [winprovit-template] for index patterns [winprovit_*]
[2023-01-31T10:06:44,992][INFO ][o.o.c.m.MetadataCreateIndexService] [node-1] [winprovit_0] creating index, cause [api], templates [winprovit-template], shards [4]/[0]
[2023-01-31T10:06:46,401][INFO ][o.o.c.r.a.AllocationService] [node-1] Cluster health status changed from [YELLOW] to [GREEN] (reason: [shards started [[winprovit_0][2], [winprovit_0][3], [winprovit_0][0]]]).
[2023-01-31T17:35:37,502][INFO ][o.o.c.m.MetadataIndexTemplateService] [node-1] adding template [winprovit-template] for index patterns [winprovit_*]
[2023-01-31T17:35:37,875][INFO ][o.o.c.m.MetadataCreateIndexService] [node-1] [winprovit_1] creating index, cause [api], templates [winprovit-template], shards [4]/[0]
[2023-01-31T17:35:38,070][INFO ][o.o.c.r.a.AllocationService] [node-1] Cluster health status changed from [YELLOW] to [GREEN] (reason: [shards started [[winprovit_1][2], [winprovit_1][3], [winprovit_1][0]]]).
[2023-02-01T10:01:08,690][WARN ][r.suppressed ] [node-1] path: /winprovit_1/_mapping, params: {index=winprovit_1}
I tried to add another Index and another stream, this time to match a rule for searching on the logs for a static field that I added to the input. And this is working, it is writing the logs to the index defined.
Also, when clicking the Name of the Stream I get no log entries in the defective streams:
Although I get them on the new stream:
I’ve also noticed that changing the stream rule to another one (e.g. this one:
stops the stream being written to the index.
I’m only able to stream the logs if I define the rule to match the static field added to the stream. If I try to use any other rule the logs aren’t streamed!
How can I troubleshoot this?