See also attached screenshot:
I would expect IP-adresses in the column "Last failed source". This expectations is based on the timestamp in the column "Last failure".
Since this is not the case: what would it take to make that happen?
I'm running ES with Kibana version 7.6.1.; including the respective Auditbeat and Packetbeat shippers.