-
addition following closed issue #26
Currently the recorded data is winlogbeat data of version 6.7 which does not follow the ECS field mappings of current version 7+ (7.8 to be specific..) is there…
-
**Background:**
As we transitioned beats to ECS in 6.x and 7.0, we made breaking changes to change `beat.hostname` to `agent.hostname`. However, `agent.hostname` is not an ECS field, and is not expe…
-
**Kibana version:**
7.9.0-BC6
This is related to this issue:
https://github.com/elastic/kibana/issues/74157
And I feel once these duplicate query issues are fixed then related issues such as t…
-
請問助教,
1.我發生了圖片右下角的error,請問要怎麼解決呢
![image](https://user-images.githubusercontent.com/40860137/95839695-e3da4780-0d75-11eb-8bc8-0644c486bf1c.png)
2.請問第a和b小題是要從哪裡登入登出呢?
![image](https://user-images…
-
How realistic is it to implement a recursive search for groups in LDAP? I would like to create a group for the kibana which includes another group, etc.
-
I looked through the ECS repo and other open issues and wasn't able to find anything related to index names. Does the ECS standard have any plans to define index naming conventions to make it easier t…
-
Adding Elasticsearch as a queryable database could open a ton of options for Shuffle. Shuffle could theoretically act and respond to endpoint eventlogs with sysmon & Mitre ATT&CK with winlogbeat for …
-
#### Describe the problem
I'm trying to send logs from a windows machine via winlogbeat to the HELK (UBUNTU).
I've set everything as listed step by step:
For server:
https://cyberwardog.blog…
-
I have a problem about different format of **event action**!
First, it appear like this
![image](https://user-images.githubusercontent.com/72923437/96286954-bf9b9680-1013-11eb-9e0d-7d7f7f83634f.png)…
-
Hi all,
I'm running into a weird issue with Packetbeat whereby the HTTP traffic reported has incorrect details logged.
The setup is this: packetbeat > local logstash > remote redis installation > lo…