Open mvanderlee opened 4 months ago
@mvanderlee For detector, are you referring to https://opensearch.org/docs/latest/security-analytics/sec-analytics-config/detectors-config/ ?
@kaituo That's right.
I can't tell you the exact config because we've stopped using Detectors and created our own alerting system
@opensearch-project/admin -- Can we please move this to https://github.com/opensearch-project/security-analytics ?
What is the bug? Upgraded a cluster from 2.11.1 to 2.15.0 and the cluster is in
red
status because the.opensearch-sap-network-detectors-queries-000007
shard is stuck initializing.How can one reproduce the bug? Steps to reproduce the behavior: No idea. Create cluster at 2.11, add detection rules, upgrade to 2.15 and observe error.
What is the expected behavior? My cluster to not die because a stupid feature can't start. If anomaly detection is broken, then only let that feature be broken, not my entire cluster!!!!!! FFS Separate user indices from system indices. The fact that this isn't done and that they are treated identical is a super stupid decision.
What is your host/environment?
Do you have any screenshots? If applicable, add screenshots to help explain your problem.
Do you have any additional context? Add any other context about the problem.