[Security Solution] Not able to create an EQL rule due to validation error #174427
Labels
bug
Fixes for quality problems that affect the customer experience
Team: SecuritySolution
Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc.
Kibana version:
7.17.16
Elasticsearch version:
7.17.16
Server OS version:
RHEL8
Browser version:
Browser OS version:
Original install method (e.g. download page, yum, from source, etc.):
Describe the bug:
Not able to create an EQL rule due to validation error
Steps to reproduce:
create new rule
Correlation type
Expected behavior:
Screenshots (if relevant):
Errors in browser console (if relevant):
Provide logs and/or server output (if relevant):
Any additional context:
Full error
{ "name": "Error", "message": "{\"error\":{\"root_cause\":[{\"type\":\"illegal_argument_exception\",\"reason\":\"request [/nswl-*,ns-business-*,windows-infra-dns-*,windows-logs-*/_eql/search] contains unrecognized parameter: [max_concurrent_shard_requests]\"}],\"type\":\"illegal_argument_exception\",\"reason\":\"request [/nswl-*,ns-business-*,windows-infra-dns-*,windows-logs-*/_eql/search] contains unrecognized parameter: [max_concurrent_shard_requests]\"},\"status\":400}", "stack": "Error: {\"error\":{\"root_cause\":[{\"type\":\"illegal_argument_exception\",\"reason\":\"request [/nswl-*,ns-business-*,windows-infra-dns-*,windows-logs-*/_eql/search] contains unrecognized parameter: [max_concurrent_shard_requests]\"}],\"type\":\"illegal_argument_exception\",\"reason\":\"request [/nswl-*,ns-business-*,windows-infra-dns-*,windows-logs-*/_eql/search] contains unrecognized parameter: [max_concurrent_shard_requests]\"},\"status\":400}\n at u (https://itsec-kibana.hq.bc:5601/47441/bundles/plugin/securitySolution/8.0.0/securitySolution.chunk.12.js:3:19795)\n at async f (https://itsec-kibana.hq.bc:5601/47441/bundles/plugin/securitySolution/8.0.0/securitySolution.chunk.12.js:3:20356)" }
The text was updated successfully, but these errors were encountered: