vulns_index - Vulnerabilitiesfindings_index - Findingslines_index - Code linespackages_index - Packagesports_index - Portsroots_index - Code rootsinputs_index - User inputsevents_index - System eventsexecutions_index - Executionsvulnerabilities_candidates_v1 - Vulnerability candidates for analysispkgs_index - Packages for analysis# General errors 
fields @timestamp, @message
| filter @message like /ERROR/| sort @timestamp desc
| limit 100
# Connection errors 
fields @timestamp, @message
| filter @message like /ConnectionError|connection.*failed|timeout/| sort @timestamp desc
| limit 50
# Cluster errors 
fields @timestamp, @message
| filter @message like /cluster.*error|node.*failed|shard.*failed/| sort @timestamp desc
| limit 50
# Slow searches 
fields @timestamp, @message
| filter @message like /took\[[0-9]+ms\], took_millis\[[0-9]+\]/| sort @timestamp desc
| limit 100
ClusterStatus - Cluster status (green, yellow, red)CPUUtilization - CPU usageFreeStorageSpace - Free spaceSearchLatency - Search latencyIndexingLatency - Indexing latencyJVMMemoryPressure - JVM memory pressurefields @timestamp, @message| filter @message like /search.*error|no.*results|zero.*results/| sort @timestamp desc
| limit 20
/aws/lambda/integrates_streams_*.fields @timestamp, @message
| filter @message like /indexing.*failed|BulkIndexError/| sort @timestamp desc
IndexingRate and IndexingLatency.ClusterStatus (red indicates serious problems).ShardAllocationStatus if available.# In log group /aws/lambda/integrates_streams_*fields @timestamp, @message
| filter @message like /Error|Exception|failed/
| parse @message "Error * - */ as errorType, errorMessage| sort @timestamp desc
| limit 50
fields @timestamp, @message
| filter @message like /BulkIndexError|bulk.*error/| sort @timestamp desc
fields @timestamp, @message
| filter @message like /bulk.*rejected|EsRejectedExecutionException/
| sort @timestamp desc
# In log group /aws/lambda/integrates_streams_*fields @timestamp, @message
| filter @message like /Error|Exception|failed/
| parse @message "Error * - */ as errorType, errorMessage| sort @timestamp desc
| limit 50
fields @timestamp, @message
| filter @message like /BulkIndexError|bulk.*error/| sort @timestamp desc
fields @timestamp, @message
| filter @message like /bulk.*rejected|EsRejectedExecutionException/
| sort @timestamp desc