See also attached screenshot:
I would expect IP-adresses in the column "Last failed source". This expectations is based on the timestamp in the column "Last failure".
Since this is not the case: what would it take to make that happen?
I'm running ES with Kibana version 7.6.1.; including the respective Auditbeat and Packetbeat shippers.
Hi, this is a question more about the data collection than Kibana (which only displays what data there is in ES).
You should try asking this in the Beats sub-forum.
Ah, I just realized now that you are in the SIEM app. I apologize, at first sight it seemed like a table created in Discover. It might be the same issue, I'll ping the SIEM team about it.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.