You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Hello,
There is a difference between wazuh-manager and opensearch timezones.Wazuh uses local timezone and creates json.gz files at 00:00 every day.But elastic works with universal time.So if i want to delete one day i have to delete data from two indexes.One have 21 hour another have 3 hour and this indexes will have another day's data.When searching there is no problem kibana will get timezone data from browser and applies.
There is no problem when search on dashboard or api.Our problem we have several years of data stored as json.gz .
We deleted them from opensearch because dont need to search frequently.But when we need to restore one day we saw that created 2 indexes.
Recreate the issue step by step:
1-)Run wazuh in a local time configured server for one day.
2-)Use recovery to json.gz in another empty wazuh cluster.
3-)Discover that days data.(there wont be a problem)
4-)Look created indexes.(There will be two indexes)
The text was updated successfully, but these errors were encountered:
|Wazuh version|Component|Install type|Install method|Platform|Timezone|
|4.3.6|wazuh-manager|Manager|Packages|Debian10|+03|
Hello,
There is a difference between wazuh-manager and opensearch timezones.Wazuh uses local timezone and creates json.gz files at 00:00 every day.But elastic works with universal time.So if i want to delete one day i have to delete data from two indexes.One have 21 hour another have 3 hour and this indexes will have another day's data.When searching there is no problem kibana will get timezone data from browser and applies.
There is no problem when search on dashboard or api.Our problem we have several years of data stored as json.gz .
We deleted them from opensearch because dont need to search frequently.But when we need to restore one day we saw that created 2 indexes.
Recreate the issue step by step:
1-)Run wazuh in a local time configured server for one day.
2-)Use recovery to json.gz in another empty wazuh cluster.
3-)Discover that days data.(there wont be a problem)
4-)Look created indexes.(There will be two indexes)
The text was updated successfully, but these errors were encountered: