Of course @Marius_Iversen there you have 2 events that are repeated.
This event keeps repeating two times a day for example, but it is not the unique one.
JSON 1:
{
"_index": ".ds-logs-google_workspace.admin-default-2023.01.19-000008",
"_id": "qcgCPpYbYXRN9LyanGrVYS32nVA=",
"_version": 1,
"_score": 0,
"_source": {
"agent": {
"name": "SRV-AWS-Eventcolector",
"id": "a594459d-0d54-4c0d-879e-f19d22c70a8b",
"type": "filebeat",
"ephemeral_id": "a1a87700-fbbe-41db-b3e3-99340c3a91e0",
"version": "8.5.2"
},
"elastic_agent": {
"id": "a594459d-0d54-4c0d-879e-f19d22c70a8b",
"version": "8.5.2",
"snapshot": false
},
"source": {
"geo": {
"continent_name": "South America",
"region_iso_code": "UY-MO",
"city_name": "Montevideo",
"country_iso_code": "UY",
"country_name": "Uruguay",
"region_name": "Departamento de Montevideo",
"location": {
"lon": -98.7654,
"lat": -98.7654
}
},
"as": {
"number": 6057,
"organization": {
"name": "Administracion Nacional de Telecomunicaciones"
}
},
"ip": "192.0.92.5",
"user": {
"domain": "altered-domain.com",
"name": "name.lastname",
"id": "104861331778014733922",
"email": "name.lastname@altered-domain.com"
}
},
"tags": [
"forwarded",
"google-workspace-admin"
],
"cloud": {
"availability_zone": "us-east-1b",
"image": {
"id": "ami-03445544beb6afeda"
},
"instance": {
"id": "i-01f017c6bf13edcb3"
},
"provider": "aws",
"service": {
"name": "EC2"
},
"machine": {
"type": "t3a.xlarge"
},
"region": "us-east-1",
"account": {
"id": "956980917244"
}
},
"input": {
"type": "httpjson"
},
"@timestamp": "2023-01-19T14:42:22.933Z",
"ecs": {
"version": "8.5.0"
},
"related": {
"ip": [
"192.0.92.5"
],
"user": [
"name.lastname",
"fernandinho.almada"
]
},
"google_workspace": {
"actor": {
"type": "USER"
},
"kind": "admin#reports#activity",
"admin": {
"user": {
"email": "fernandinho.almada@altered-domain.com"
}
},
"event": {
"type": "USER_SETTINGS"
}
},
"data_stream": {
"namespace": "default",
"type": "logs",
"dataset": "google_workspace.admin"
},
"organization": {
"id": "C025zio51"
},
"event": {
"agent_id_status": "verified",
"ingested": "2023-01-19T15:53:20Z",
"provider": "admin",
"created": "2023-01-19T15:53:19.285Z",
"kind": "event",
"action": "CHANGE_PASSWORD",
"id": "-6264539690912704257",
"category": [
"iam"
],
"type": [
"change",
"user"
],
"dataset": "google_workspace.admin"
},
"user": {
"domain": "altered-domain.com",
"name": "name.lastname",
"id": "104861331778014733922",
"email": "name.lastname@altered-domain.com",
"target": {
"domain": "altered-domain.com",
"name": "fernandinho.almada",
"email": "fernandinho.almada@altered-domain.com"
}
}
},
"fields": {
"elastic_agent.version": [
"8.5.2"
],
"event.category": [
"iam"
],
"source.user.email": [
"name.lastname@altered-domain.com"
],
"cloud.availability_zone": [
"us-east-1b"
],
"source.user.name.text": [
"name.lastname"
],
"user.target.email": [
"fernandinho.almada@altered-domain.com"
],
"source.geo.region_name": [
"Departamento de Montevideo"
],
"google_workspace.actor.type": [
"USER"
],
"source.ip": [
"192.0.92.5"
],
"agent.name": [
"SRV-AWS-Eventcolector"
],
"source.geo.region_iso_code": [
"UY-MO"
],
"user.target.name.text": [
"fernandinho.almada"
],
"event.agent_id_status": [
"verified"
],
"event.kind": [
"event"
],
"google_workspace.event.type": [
"USER_SETTINGS"
],
"source.geo.city_name": [
"Montevideo"
],
"cloud.region": [
"us-east-1"
],
"user.id": [
"104861331778014733922"
],
"input.type": [
"httpjson"
],
"data_stream.type": [
"logs"
],
"user.target.name": [
"fernandinho.almada"
],
"tags": [
"forwarded",
"google-workspace-admin"
],
"related.user": [
"name.lastname",
"fernandinho.almada"
],
"cloud.machine.type": [
"t3a.xlarge"
],
"cloud.provider": [
"aws"
],
"event.provider": [
"admin"
],
"cloud.service.name": [
"EC2"
],
"agent.id": [
"a594459d-0d54-4c0d-879e-f19d22c70a8b"
],
"ecs.version": [
"8.5.0"
],
"event.created": [
"2023-01-19T15:53:19.285Z"
],
"google_workspace.admin.user.email": [
"fernandinho.almada@altered-domain.com"
],
"organization.id": [
"C025zio51"
],
"agent.version": [
"8.5.2"
],
"source.user.name": [
"name.lastname"
],
"source.as.number": [
6057
],
"user.name": [
"name.lastname"
],
"source.geo.location": [
{
"coordinates": [
-98.7654,
-98.7654
],
"type": "Point"
}
],
"cloud.instance.id": [
"i-01f017c6bf13edcb3"
],
"agent.type": [
"filebeat"
],
"event.module": [
"google_workspace"
],
"user.email": [
"name.lastname@altered-domain.com"
],
"related.ip": [
"192.0.92.5"
],
"source.geo.country_iso_code": [
"UY"
],
"user.target.domain": [
"altered-domain.com"
],
"source.user.id": [
"104861331778014733922"
],
"elastic_agent.snapshot": [
false
],
"user.domain": [
"altered-domain.com"
],
"source.as.organization.name.text": [
"Administracion Nacional de Telecomunicaciones"
],
"elastic_agent.id": [
"a594459d-0d54-4c0d-879e-f19d22c70a8b"
],
"data_stream.namespace": [
"default"
],
"source.as.organization.name": [
"Administracion Nacional de Telecomunicaciones"
],
"source.geo.continent_name": [
"South America"
],
"google_workspace.kind": [
"admin#reports#activity"
],
"cloud.image.id": [
"ami-03445544beb6afeda"
],
"event.action": [
"CHANGE_PASSWORD"
],
"event.ingested": [
"2023-01-19T15:53:20.000Z"
],
"@timestamp": [
"2023-01-19T14:42:22.933Z"
],
"cloud.account.id": [
"956980917244"
],
"data_stream.dataset": [
"google_workspace.admin"
],
"event.type": [
"change",
"user"
],
"agent.ephemeral_id": [
"a1a87700-fbbe-41db-b3e3-99340c3a91e0"
],
"source.user.domain": [
"altered-domain.com"
],
"source.geo.country_name": [
"Uruguay"
],
"event.id": [
"-6264539690912704257"
],
"event.dataset": [
"google_workspace.admin"
],
"user.name.text": [
"name.lastname"
]
}
}
JSON 2:
{
"_index": ".ds-logs-google_workspace.admin-default-2023.01.19-000008",
"_id": "Bq3vDX+YdBPKMO45DIrHAu7KQiE=",
"_version": 1,
"_score": 0,
"_source": {
"agent": {
"name": "SRV-AWS-Eventcolector",
"id": "a594459d-0d54-4c0d-879e-f19d22c70a8b",
"type": "filebeat",
"ephemeral_id": "a1a87700-fbbe-41db-b3e3-99340c3a91e0",
"version": "8.5.2"
},
"elastic_agent": {
"id": "a594459d-0d54-4c0d-879e-f19d22c70a8b",
"version": "8.5.2",
"snapshot": false
},
"source": {
"geo": {
"continent_name": "South America",
"region_iso_code": "UY-MO",
"city_name": "Montevideo",
"country_iso_code": "UY",
"country_name": "Uruguay",
"region_name": "Departamento de Montevideo",
"location": {
"lon": -98.7654,
"lat": -98.7654
}
},
"as": {
"number": 6057,
"organization": {
"name": "Administracion Nacional de Telecomunicaciones"
}
},
"ip": "192.0.92.5",
"user": {
"domain": "altered-domain.com",
"name": "name.lastname",
"id": "104861331778014733922",
"email": "name.lastname@altered-domain.com"
}
},
"tags": [
"forwarded",
"google-workspace-admin"
],
"cloud": {
"image": {
"id": "ami-03445544beb6afeda"
},
"availability_zone": "us-east-1b",
"instance": {
"id": "i-01f017c6bf13edcb3"
},
"provider": "aws",
"machine": {
"type": "t3a.xlarge"
},
"service": {
"name": "EC2"
},
"region": "us-east-1",
"account": {
"id": "956980917244"
}
},
"input": {
"type": "httpjson"
},
"@timestamp": "2023-01-19T14:42:22.933Z",
"ecs": {
"version": "8.5.0"
},
"related": {
"ip": [
"192.0.92.5"
],
"user": [
"name.lastname",
"fernandinho.almada"
]
},
"google_workspace": {
"actor": {
"type": "USER"
},
"kind": "admin#reports#activity",
"admin": {
"old_value": "false",
"user": {
"email": "fernandinho.almada@altered-domain.com"
},
"new_value": "true"
},
"event": {
"type": "USER_SETTINGS"
}
},
"data_stream": {
"namespace": "default",
"type": "logs",
"dataset": "google_workspace.admin"
},
"organization": {
"id": "C025zio51"
},
"event": {
"agent_id_status": "verified",
"ingested": "2023-01-19T15:53:20Z",
"provider": "admin",
"created": "2023-01-19T15:53:19.285Z",
"kind": "event",
"action": "CHANGE_PASSWORD_ON_NEXT_LOGIN",
"id": "-6264539690912704257",
"category": [
"iam"
],
"type": [
"change",
"user"
],
"dataset": "google_workspace.admin"
},
"user": {
"domain": "altered-domain.com",
"name": "name.lastname",
"id": "104861331778014733922",
"email": "name.lastname@altered-domain.com",
"target": {
"domain": "altered-domain.com",
"name": "fernandinho.almada",
"email": "fernandinho.almada@altered-domain.com"
}
}
},
"fields": {
"elastic_agent.version": [
"8.5.2"
],
"event.category": [
"iam"
],
"source.user.email": [
"name.lastname@altered-domain.com"
],
"cloud.availability_zone": [
"us-east-1b"
],
"source.user.name.text": [
"name.lastname"
],
"user.target.email": [
"fernandinho.almada@altered-domain.com"
],
"source.geo.region_name": [
"Departamento de Montevideo"
],
"google_workspace.actor.type": [
"USER"
],
"source.ip": [
"192.0.92.5"
],
"agent.name": [
"SRV-AWS-Eventcolector"
],
"source.geo.region_iso_code": [
"UY-MO"
],
"user.target.name.text": [
"fernandinho.almada"
],
"event.agent_id_status": [
"verified"
],
"event.kind": [
"event"
],
"google_workspace.event.type": [
"USER_SETTINGS"
],
"source.geo.city_name": [
"Montevideo"
],
"cloud.region": [
"us-east-1"
],
"user.id": [
"104861331778014733922"
],
"google_workspace.admin.new_value": [
"true"
],
"input.type": [
"httpjson"
],
"data_stream.type": [
"logs"
],
"user.target.name": [
"fernandinho.almada"
],
"tags": [
"forwarded",
"google-workspace-admin"
],
"related.user": [
"name.lastname",
"fernandinho.almada"
],
"cloud.machine.type": [
"t3a.xlarge"
],
"cloud.provider": [
"aws"
],
"event.provider": [
"admin"
],
"cloud.service.name": [
"EC2"
],
"agent.id": [
"a594459d-0d54-4c0d-879e-f19d22c70a8b"
],
"ecs.version": [
"8.5.0"
],
"event.created": [
"2023-01-19T15:53:19.285Z"
],
"google_workspace.admin.user.email": [
"fernandinho.almada@altered-domain.com"
],
"organization.id": [
"C025zio51"
],
"agent.version": [
"8.5.2"
],
"source.user.name": [
"name.lastname"
],
"source.as.number": [
6057
],
"user.name": [
"name.lastname"
],
"source.geo.location": [
{
"coordinates": [
-98.7654,
-98.7654
],
"type": "Point"
}
],
"cloud.instance.id": [
"i-01f017c6bf13edcb3"
],
"agent.type": [
"filebeat"
],
"event.module": [
"google_workspace"
],
"user.email": [
"name.lastname@altered-domain.com"
],
"related.ip": [
"192.0.92.5"
],
"source.geo.country_iso_code": [
"UY"
],
"user.target.domain": [
"altered-domain.com"
],
"source.user.id": [
"104861331778014733922"
],
"elastic_agent.snapshot": [
false
],
"user.domain": [
"altered-domain.com"
],
"google_workspace.admin.old_value": [
"false"
],
"source.as.organization.name.text": [
"Administracion Nacional de Telecomunicaciones"
],
"elastic_agent.id": [
"a594459d-0d54-4c0d-879e-f19d22c70a8b"
],
"data_stream.namespace": [
"default"
],
"source.as.organization.name": [
"Administracion Nacional de Telecomunicaciones"
],
"source.geo.continent_name": [
"South America"
],
"google_workspace.kind": [
"admin#reports#activity"
],
"cloud.image.id": [
"ami-03445544beb6afeda"
],
"event.action": [
"CHANGE_PASSWORD_ON_NEXT_LOGIN"
],
"event.ingested": [
"2023-01-19T15:53:20.000Z"
],
"@timestamp": [
"2023-01-19T14:42:22.933Z"
],
"cloud.account.id": [
"956980917244"
],
"data_stream.dataset": [
"google_workspace.admin"
],
"event.type": [
"change",
"user"
],
"agent.ephemeral_id": [
"a1a87700-fbbe-41db-b3e3-99340c3a91e0"
],
"source.user.domain": [
"altered-domain.com"
],
"source.geo.country_name": [
"Uruguay"
],
"event.id": [
"-6264539690912704257"
],
"event.dataset": [
"google_workspace.admin"
],
"user.name.text": [
"name.lastname"
]
}
}
I altered some values for security reasons.