elastic / integrations

Elastic Integrations
https://www.elastic.co/integrations
Other
194 stars 418 forks source link

[system] Windows Security - Use Managment Events dashboard missing forwarded events #10431

Closed nicpenning closed 1 month ago

nicpenning commented 1 month ago

It seems that the windows.forwarded is missing from some visualizations resulting in missing data:

image

Exploring these visuals in discover look something like this:

image

Note that the dataset is set twice. Likely the solution is to remove the search query in the bar with the dataset since it is redundant.

Removing that part of the search filter provides results like so: image

elasticmachine commented 1 month ago

Pinging @elastic/sec-windows-platform (Team:Security-Windows Platform)