In the Watchlist docs, we should mention that for Rule Based Data Sources > Index Pattern, the selected index pattern must have the @timestamp field. Selecting an index pattern without a @timestamp field will cause no entities ever to be synced. On the Kibana side, we're adding validation to that field in the UI in elastic/kibana#287385
This has been a requirement since Watchlists were added in 9.4
In the Watchlist docs, we should mention that for
Rule Based Data Sources > Index Pattern, the selected index pattern must have the@timestampfield. Selecting an index pattern without a@timestampfield will cause no entities ever to be synced. On the Kibana side, we're adding validation to that field in the UI in elastic/kibana#287385This has been a requirement since Watchlists were added in 9.4