elastic / elastic/integrations
[Elasticsearch]: New index_pivot transform isn't starting
- Dominant language
- Handlebars
- Stars
- 333
- Forks
- 647
- Avg merge
- 3d 4h
- Merged PRs (30d)
- 209
Description
### Integration Name
Elasticsearch [elasticsearch]
### Dataset Name
elasticsearch.index
### Integration Version
8.16.0
### Agent Version
8.17.1
### OS Version and Architecture
RHEL 8.10
### Report
I am looking to make use of the new `logs-elasticsearch.index_pivot-default-0.1.0` transform / the `[Elasticsearch] Indices & data streams usage (Technical Preview/Beta)` dashboard that was added recently. I just updated my cluster to 8.17.1 and agents to the same, but the transform wasn' starting.
I was reading along the docs at https://www.elastic.co/guide/en/integrations/current/elasticsearch.html#elasticsearch-indices-and-data-streams-usage-analysis about manually starting the transform but that had me landing on the following error:
```
Transform encountered an exception: [Could not create destination index [monitoring-indices] for transform [logs-elasticsearch.index_pivot-default-0.1.0]]; Will automatically retry [30/-1]
```
I was coming here to report this and while looking up the integration version number noticed that in the Assets tab of the integration, it had a button I needed to push to "Reauthorize" the integration. Doing that now is allowing the transform to run successfully now.
Perhaps a note could/should be added to the https://www.elastic.co/guide/en/integrations/current/elasticsearch.html#elasticsearch-indices-and-data-streams-usage-analysis page to specify that this additional action may be needed?
Unfortunately, I didn't grab a screenshot of the "re-authorize" button while I was there, and now it is gone. Happy to provide additional details though if I can / if useful.
Contributor guide
Assessment
This issue has not been assessed yet.