After a DX SaaS update or migration to OpenSearch 3.x, users may encounter the following issues in the "Logs for Triage" (Discover) pane:
logs_cust_log4j_abcdef).The issue is caused by role permissions that were not properly applied to certain tenants during the OpenSearch migration. This permission gap prevents the UI from correctly executing CRUD (Create, Read, Update, Delete) operations on scripted fields, even though the UI may not always display an explicit access error. Additionally, older scripted field syntax may be incompatible with the newer OpenSearch version.
Engineering fixed the role permission issue in production for impacted tenants. You can update the scripted fields to the new syntax to restore dashboard functionality.