Winlogbeat 7.6.1. Really easy drop 2 events is failing. I get hundreds of thousands of these events a day. They consist of 95% of the winlog traffic that is sent to the elastic stack.
Copy/Paste which from other threads and nothing. Changing drop to when only does nothing. Here is the the example setup I have on a few machines and nothing.
I've checked both the sysmom for the event ID's and they are not present. Events are still being sent to Elastic and it's only coming from the security event log.
Any tips to get these things dropped would be amazing.
You cannot have more than one processors block in the same object. The last one will take precedence. You can try a few things to see this. Paste your config into http://www.yamllint.com/. Or run .\winlogbeat.exe export config.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.