Errors in Discover Pane and Issues Updating Scripted Fields
search cancel

Errors in Discover Pane and Issues Updating Scripted Fields

book

Article ID: 445336

calendar_today

Updated On:

Products

DX SaaS

Issue/Introduction

After a DX SaaS update or migration to OpenSearch 3.x, users may encounter the following issues in the "Logs for Triage" (Discover) pane:

  • Errors (such as "Internal error 500") when trying to view data for specific log patterns (e.g., logs_cust_log4j_abcdef).
  • Scripted fields that were deleted still appear in the list.
  • Dashboards using scripted fields no longer function.
  • Attempts to edit or save scripted fields result in indefinite loading or the changes failing to persist.

Environment

  • DX O2 SaaS

Cause

The issue is caused by role permissions that were not properly applied to certain tenants during the OpenSearch migration. This permission gap prevents the UI from correctly executing CRUD (Create, Read, Update, Delete) operations on scripted fields, even though the UI may not always display an explicit access error. Additionally, older scripted field syntax may be incompatible with the newer OpenSearch version.

Resolution

Engineering fixed the role permission issue in production for impacted tenants. You can update the scripted fields to the new syntax to restore dashboard functionality.