[event log] query should be over all version indices, not just the current version indices #81274
Labels
bug
Fixes for quality problems that affect the customer experience
Feature:EventLog
Team:ResponseOps
Label for the ResponseOps team (formerly the Cases and Alerting teams)
In the code below, we are querying the event log using the alias we create to write event docs to the indices:
kibana/x-pack/plugins/event_log/server/event_log_client.ts
Lines 94 to 100 in b362ed1
That alias name - and other es-related names - are generated here:
kibana/x-pack/plugins/event_log/server/es/names.ts
Lines 22 to 37 in b362ed1
For v7.10.0, the alias name will be
.kibana-event-log-7.10.0
. This will limit searches to only the events generated by the current version of Kibana. We should be able to search older versions as well - the mappings have not changed significantly since the beginnings. Clearly we need some thoughts about the future where the mappings could change in incompatible ways, and consider what happens when the event log becomes a datastream.For now, it seems like we should use
EsNames.indexPattern
, which would be set to the string.kibana-event-log-*
, for these queries.The text was updated successfully, but these errors were encountered: