bitsensor / elastalert-kibana-plugin

ElastAlert Kibana Plugin
https://bitsensor.io/blog/elastalert-kibana-plugin-centralized-logging-with-integrated-alerting
Other
556 stars 118 forks source link

Issues with winlogbeats #140

Closed Dair8 closed 4 years ago

Dair8 commented 4 years ago

Hello,

I have a couple of issues with alerts with logs from winlogbeats.

I have alerts created that trigger correctly and send that alert to TheHive, but then I found two issues:

The only observables that I receive on theHive are those without . ,i.e: msg: "{match[message]}"

Nevertheless, the fields host.XXX appear in ELK.

I don't know if both issues are related.

Can you help?

Dair8 commented 4 years ago

Solved in https://github.com/TheHive-Project/TheHive/issues/1209