Closed kclinden closed 19 minutes ago
Looks like a problem with Data Prepper rather than with the Wazuh Indexer. Which version of Data Prepper did you use? I remember we used Data Prepper on the very early stages of the Amazon Security Lake integration, and it did work for us. I compared the pipelines and they are almost identical.
We finally decided to use Logstash because it was more stable than Data Prepper (see #113).
We need compatibility mode enabled because of Filebeat. I can see that Data Prepper has an undocumented option to override this problem. I'm closing this issue because of that.
Describe the bug When using OpenSearch Data Prepper to ingest data from the Wazuh Indexer it is not returning the distribution value which is used by the opensearch client to determine if Wazuh is using elastic search or opensearch.
I opened a similar issue on Data Prepper's project. https://github.com/opensearch-project/data-prepper/issues/4654
Desired return from
GET /
Wazuh Return Value:
Data Prepper Pipeline:
Expected behavior Opensearch api returns distribution info
Plugins none
Additional context Data Prepper Error: