@andrewkroh Thanks for the quick reply! Hope I have pasted it correctly below.
{
"_index": "auditbeat-6.2.3-2018.04.17",
"_type": "doc",
"_id": "QUeK02IBMgsju5oVqjTK",
"_version": 1,
"_score": null,
"_source": {
"event": {
"module": "auditd",
"category": "audit-rule",
"action": "opened-file",
"type": "syscall"
},
"@version": "1",
"host": "ptc38501-01.ptc.com",
"file": {
"mode": "0664",
"uid": "568",
"group": "twc",
"gid": "595",
"inode": "258379478",
"owner": "n3burd",
"device": "00:00",
"path": "ScanConductor.java"
},
"tags": [
"ptc_dir_access",
"beats_input_raw_event"
],
"user": {
"egid": "501",
"uid": "0",
"sgid": "501",
"name_map": {
"egid": "ptc",
"uid": "root",
"sgid": "ptc",
"fsgid": "ptc",
"fsuid": "n3burd",
"auid": "root",
"gid": "root",
"euid": "n3burd",
"suid": "n3burd"
},
"fsgid": "501",
"fsuid": "568",
"gid": "0",
"auid": "0",
"euid": "568",
"suid": "568"
},
"beat": {
"version": "6.2.3",
"hostname": "ptc38501-01.ptc.com",
"name": "ptc-desk"
},
"process": {
"cwd": "/PTC/twc/pm/9_PTC Team/NickB/maven-shared-utils-0.4/shadow-most-maven-shared-utils-0.4-scanresults/base/maven-shared-utils-0.4-source-release-0/maven-shared-utils-0.4/src/main/java/org/apache/maven/shared/utils/io",
"pid": "27682",
"name": "smbd",
"exe": "/usr/sbin/smbd",
"ppid": "28912"
},
"auditd": {
"sequence": 1165041009,
"summary": {
"how": "/usr/sbin/smbd",
"object": {
"primary": "ScanConductor.java",
"type": "file"
},
"actor": {
"primary": "root",
"secondary": "root"
}
},
"session": "16220",
"result": "success",
"paths": [
{
"item": "0",
"mode": "042775",
"name": "2F5054432F7477632F706D2F395F505443205465616D2F4E69636B422F6D6176656E2D7368617265642D7574696C732D302E342F736861646F772D6D6F73742D6D6176656E2D7368617265642D7574696C732D302E342D7363616E726573756C74732F626173652F6D6176656E2D7368617265642D7574696C732D302E342D736F757263652D72656C656173652D302F6D6176656E2D7368617265642D7574696C732D302E342F7372632F6D61696E2F6A6176612F6F72672F6170616368652F6D6176656E2F7368617265642F7574696C732F696F",
"dev": "fd:03",
"nametype": "PARENT",
"ogid": "595",
"rdev": "00:00",
"ouid": "568",
"inode": "141116713"
},
{
"item": "1",
"mode": "0100664",
"name": "ScanConductor.java",
"rdev": "00:00",
"ogid": "595",
"nametype": "CREATE",
"dev": "fd:03",
"ouid": "568",
"inode": "258379478"
}
],
"data": {
"a3": "0",
"tty": "(none)",
"arch": "x86_64",
"a1": "20042",
"syscall": "open",
"exit": "86",
"a2": "1b4",
"a0": "7fb6818d01e0"
}
},
"@timestamp": "2018-04-17T12:18:20.997Z"
},
"fields": {
"@timestamp": [
"2018-04-17T12:18:20.997Z"
]
},
"highlight": {
"tags": [
"@kibana-highlighted-field@ptc_dir_access@/kibana-highlighted-field@"
]
},
"sort": [
1523967500997
]
}