-
Notifications
You must be signed in to change notification settings - Fork 427
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[Windows Integration]: Error installing windows 1.47.0 #10750
Comments
Pinging @elastic/elastic-agent-data-plane (Team:Elastic-Agent-Data-Plane) |
Thank you @andrewkroh |
Pinging @elastic/sec-windows-platform (Team:Security-Windows Platform) |
I was not able to reproduce this on 8.13.4. I spun up a new cluster for this test. Did you do anything different 🤔? elastic-8.13.4-windows-1.47.0-install-assets.mov |
Nope: 2024-08-13.10-08-40.mp4Nothing different. Doesnt work and if I reboot the machine, I get the screen to install the integration again. Elastic, Kibana and Logstash all on the same machine. |
Did you have any previous version of the integration installed before? Or is this a fresh install? |
Fresh install. Not a upgraded build from anything previous. Fortigate integration is installed, configured, and setup and firewalls are sending logs to here but besides that.....nothing else I could think up |
can you check if you have any |
I am having the same issue. I am trying to upgrade the Windows integration from 1.2.2 to 1.47.0. I do not have any |
Deleting Windows related data streams is what allowed me to update the integration without error. I didn't see any indices originally because they were hidden indices. Had to toggle on "include hidden indices" and discovered I actually did have these:
I deleted the associated data streams:
I also added the below to these component templates
|
Thanks for confirming that @jameswiggins , in your case it seems it was the upgrade process that did not let you add the analyzer with the open datastreams. @riahc3 can you confirm you do not have such datastreams/indices, also? cc @elastic/fleet maybe something to take a look into here |
CONFIRMED. In data stream, I searched logs-windows.powershell , deleted everything and the integration installed perfectly. Seems to be a bug. |
I've been looking into that and ES documetation states:
Doing some testing, I believe I managed to set the analyser using the following PUT request:
Looking at the git history, this analyser got added in I'll look if there is a way to get the integration to update without deleting the datastreams. |
To upgrade the integration I only needed to delete:
|
Integration Name
Windows [windows]
Dataset Name
No response
Integration Version
1.47.0
Agent Version
8.13.4
Agent Output Type
elasticsearch
Elasticsearch Version
8.13.4
OS Version and Architecture
Windows 10, Windows 11 and Debian 12
Software/API Version
No response
Error Message
Error installing windows 1.47.0: mapper_parsing_exception Caused by: illegal_argument_exception: analyzer [powershell_script_analyzer] has not been configured in mappings Root causes: mapper_parsing_exception: Failed to parse mapping: analyzer [powershell_script_analyzer] has not been configured in mappings
Event Original
No response
What did you do?
I tried to add Windows Integration
What did you see?
Error installing windows 1.47.0: mapper_parsing_exception Caused by: illegal_argument_exception: analyzer [powershell_script_analyzer] has not been configured in mappings Root causes: mapper_parsing_exception: Failed to parse mapping: analyzer [powershell_script_analyzer] has not been configured in mappings
What did you expect to see?
The integration properly added
Anything else?
No response
The text was updated successfully, but these errors were encountered: