alphasoc / nfr

A lightweight tool to score network traffic and flag anomalies
https://alphasoc.com
Other
122 stars 19 forks source link

elastic: append root_cause array to error message #90

Closed kmroz closed 2 years ago

kmroz commented 2 years ago

Should allow for better identification of certain types of search failures.

ie: 13 shards; date parse failure

time="2022-03-21T10:23:31+01:00" level=error msg="fetch events: search api error: [400 Bad Request] search_phase_execution_exception: all shards failed; parse_exception: failed to parse date field [2022-03-21T10:23:31.253419+01:00] with format [strict_date_time_no_millis]; parse_exception: failed to parse date field [2022-03-21T10:23:31.253419+01:00] with format [strict_date_time_no_millis]; parse_exception: failed to parse date field [2022-03-21T10:23:31.253419+01:00] with format [strict_date_time_no_millis]; parse_exception: failed to parse date field [2022-03-21T10:23:31.253419+01:00] with format [strict_date_time_no_millis]; parse_exception: failed to parse date field [2022-03-21T10:23:31.253419+01:00] with format [strict_date_time_no_millis]; parse_exception: failed to parse date field [2022-03-21T10:23:31.253419+01:00] with format [strict_date_time_no_millis]; parse_exception: failed to parse date field [2022-03-21T10:23:31.253419+01:00] with format [strict_date_time_no_millis]; parse_exception: failed to parse date field [2022-03-21T10:23:31.253419+01:00] with format [strict_date_time_no_millis]; parse_exception: failed to parse date field [2022-03-21T10:23:31.253419+01:00] with format [strict_date_time_no_millis]; parse_exception: failed to parse date field [2022-03-21T10:23:31.253419+01:00] with format [strict_date_time_no_millis]; parse_exception: failed to parse date field [2022-03-21T10:23:31.253419+01:00] with format [strict_date_time_no_millis]; parse_exception: failed to parse date field [2022-03-21T10:23:31.253419+01:00] with format [strict_date_time_no_millis]; parse_exception: failed to parse date field [2022-03-21T10:23:31.253419+01:00] with format [strict_date_time_no_millis]" name=ip-001