I have an ELK stack hosted on elastic cloud. I have multiple different customers who regularly log in to view their respected dashboards.
I would like to collect logs showing successful and unsuccessful login attempts.
I used the API to see which setting i have enabled, and the only one concerning xpack was:
So my question is, what concrete steps should i take to log and collect the events mentioned above?
Especially what settings should i change, and where?
I know how to use the APIs and that i can modify
Kibana.yml in the edit section of the cloud management dashboard, i just don't understand what exactly i'm supposed to do.
Thank you in advance.