Skip to content

[CrowdStrike]: A empty index was created and missing log field @timestamp #18462

@hardyqiu

Description

@hardyqiu

Integration Name

CrowdStrike [crowdstrike]

Dataset Name

dataset is alright

Integration Version

3.14.0

Agent Version

8.19.6

Agent Output Type

logstash

Elasticsearch Version

8.19

OS Version and Architecture

Ubuntu

Software/API Version

No response

Error Message

I upgrade CrowdStrike integrations from 2.8.0 to 3.14.0 yesterday, after that, in Security -> detection prompt a warning message for all rule.

Image

The warning message is The following indices are missing the timestamp field "@timestamp": ["logs-crowdstrike_lookup.dest_aidmaster-1"]

Image

And this index "logs-crowdstrike_lookup.dest_aidmaster-1" is empty without any data inside, the index created time aligns with when I upgraded the integration.
So far, this warning message hasn't affected my ELK function, but I would like to know how to resolve this issue.
Much appreciated.

Event Original

No response

What did you do?

1

What did you see?

1

What did you expect to see?

1

Anything else?

No response

Metadata

Metadata

Assignees

Labels

Integration:crowdstrikeCrowdStrikeTeam:Security-Service IntegrationsSecurity Service Integrations team [elastic/security-service-integrations]bugSomething isn't working, use only for issues

Type

No type
No fields configured for issues without a type.

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions