[Alerting] Log more descriptive error messages when runtime field mappings are updated to be incompatible with original query #95516
Labels
Feature:Alerting
Team:ResponseOps
Label for the ResponseOps team (formerly the Cases and Alerting teams)
Based on this investigation, we have determined that when runtime field mappings are updated to be incompatible with the originally defined type (
date
tokeyword
for a field used in a time range query for example, theindex-threshold
andes-query
stack rule executions will fail with asearch_phase_execution_exception
that is logged in the event log. The actual error coming back from ES is usually more descriptive. It would be helpful to capture these more descriptive error messages to aid in debugging rule execution failures.Some examples of the errors coming back from ES:
The text was updated successfully, but these errors were encountered: