I tried to implement a detection rule (query rule) for the Elastic SIEM module (Elasticsearch Version 7.10.0) and got this error message.
I wondered how an error in the system index .siem-signals-default could occur. Also in this index the host field was an object.
When I looked for the error I found out that my custom index was indexed incorrectly. I would recommend to formulate the error message more clearly to something like:
Bulk Indexing of signals failed: object mapping for [host] tried to parse field [host] as object, but found a concrete value name: "hostname_in_custom_index" id: "..." rule id: "..." signals index: "custom_index"
(b/c "test" is the name of the rule and not the name from the incorrectly parsed field host.)
I tried to implement a detection rule (query rule) for the Elastic SIEM module (Elasticsearch Version 7.10.0) and got this error message.
I wondered how an error in the system index
.siem-signals-default
could occur. Also in this index thehost
field was an object.When I looked for the error I found out that my custom index was indexed incorrectly. I would recommend to formulate the error message more clearly to something like:
(b/c "test" is the name of the rule and not the name from the incorrectly parsed field
host
.)