Closed apolloclark closed 6 years ago
Thanks for your interest and sorry for the trouble that you're having.
I think that this is not an Elasticsearch issue, but instead an ingest issue. Would you start by opening an issue on elastic/beats? I think that they will be able to provide better support than we can here.
Will do, thanks! https://github.com/elastic/beats/issues/7742
Environment
Description
When using Auditbeat, shipping to Logstash, into Elasticsearch, the default Auditbeat dashboards do not load. However, when going Auditbeat -> Elasticsearch -> Kibana, the Auditbeat dashboards do work. Notice in the screenshot that field "auditd.data.syscall" is marked as "aggregatable" in the working version, but is not "aggregatable" in the broken version.
Auditbeat -> Logstash -> Elasticsearch -> Kibana (Broken)
Auditbeat -> Elasticsearch -> Kibana (Working)
Steps to reproduce:
Logs: