I'm back from vacation and still at a loss with this issue. I managed to correct the query:
"query": {
"range" : {
"@timestamp" : {
"gte" : "2018-11-01", "lte" : "now"
}
}
}, "sort": [ "@timestamp" ]
(because I needed from Nov 1st instead of Jan 1st, so everything is nice now)
But I'm still not getting the filter result:
[2020-03-09T21:21:09,553][DEBUG][logstash.pipeline ] filter received {"event"=>{"EventTimestamp"=>nil, "FQUser"=>"<user>", "AcctStatusType"=>nil, "MSAcctEAPType"=>nil, "PacketType"=>"3", "TunnelPreference"=>nil, "AcctMultiSsnID"=>nil, "ClientVendor"=>nil, "TunnelClientEndpt"=>nil, "@version"=>"1", "AcctAuthentic"=>nil, "Date"=>"11/24/2018", "EAPFriendlyName"=>nil, "MSRASVendor"=>nil, "@timestamp"=>2018-11-24T05:14:17.000Z, "MSMPPEEncryptionPolicy"=>nil, "AcctSessionTime"=>nil, "ClientFriendlyName"=>nil, "CallbackNumber"=>nil, "MSRASClientVersion"=>nil, "FramedIPAddress"=>nil, "host"=>"<host>", "NASIdentifier"=>nil, "SessionTimeout"=>nil, "MSAcctAuthType"=>nil, "ProviderName"=>nil, "AcctInterimInterval"=>nil, "type"=>"rras_log", "PolicyName"=>nil, "ServiceType"=>nil, "CalledStationID"=>nil, "NASPortType"=>nil, "ClientIPAddress"=>nil, "ProxyPolicyName"=>"Microsoft Routing and Remote Access Service Policy", "MSMPPEEncryptionTypes"=>nil, "MSRASClientName"=>nil, "RemoteServerAddress"=>nil, "TunnelServerEndpt"=>nil, "TunnelPvtGroupID"=>nil, "ServiceName"=>"RAS", "MSCHAPError"=>nil, "ProviderType"=>"1", "ConnectInfo"=>nil, "AcctTunnelConn"=>nil, "UserName"=>nil, "NASPort"=>nil, "AuthenticationType"=>"4", "MSCHAPDomain"=>nil, "AcctOutputPackets"=>nil, "Time"=>"03:14:17", "AcctInputPackets"=>nil, "PortLimit"=>nil, "CallingStationID"=>nil, "ComputerName"=>"<server>", "AcctTerminateCause"=>nil, "TunnelType"=>nil, "AcctInputOctets"=>nil, "TerminationAction"=>nil, "IdleTimeout"=>nil, "TunnelMediumType"=>nil, "message"=>"\"<server>\",\"RAS\",11/24/2018,03:14:17,3,,\"<user>\",,,,,,,,,,,,,,,,,4,,48,\"311 1 <ip> 05/26/2018 16:09:57 100364\",,,,,,,,,\"100365\",,,,,,,,,,,,,,,,,,,,,,,,,\"Microsoft Routing and Remote Access Service Policy\",1,,,,\r", "NASIPAddress"=>nil, "AcctSessionID"=>"100365", "path"=>"/var/leitura/entrada_vpn_full.csv", "FramedProtocol"=>nil, "TunnelAssignmentID"=>nil, "AcctOutputOctets"=>nil, "MSRASVersion"=>nil, "AcctLinkCount"=>nil, "ReasonCode"=>"48", "AcctDelayTime"=>nil, "Class"=>"311 1 <ip> 05/26/2018 16:09:57 100364"}}
[2020-03-09T21:21:09,588][DEBUG][logstash.filters.elasticsearch] Querying elasticsearch for lookup {:params=>{:index=>"rras_vpn-2018.11.24", :q=>"PacketType:1 AND AcctSessionID:100365 AND FQUser:<user>", :size=>1, :sort=>"@timestamp:desc"}}
[2020-03-09T21:21:09,588][INFO ][logstash.filters.elasticsearch] New ElasticSearch filter client {:hosts=>["http://10.122.151.127:9200"]}
C:/Users/c070054/Downloads/logstash-6.8.6/vendor/bundle/jruby/2.5.0/gems/logstash-filter-fingerprint-3.2.1/lib/logstash/filters/fingerprint.rb:181: warning: constant ::Fixnum is deprecated
[2020-03-09T21:21:09,819][DEBUG][logstash.pipeline ] output received {"event"=>{"EventTimestamp"=>nil, "FQUser"=>"<user>", "AcctStatusType"=>nil, "MSAcctEAPType"=>nil, "PacketType"=>"3", "TunnelPreference"=>nil, "AcctMultiSsnID"=>nil, "ClientVendor"=>nil, "TunnelClientEndpt"=>nil, "@version"=>"1", "AcctAuthentic"=>nil, "Date"=>"11/24/2018", "EAPFriendlyName"=>nil, "MSRASVendor"=>nil, "@timestamp"=>2018-11-24T05:14:17.000Z, "MSMPPEEncryptionPolicy"=>nil, "AcctSessionTime"=>nil, "ClientFriendlyName"=>nil, "CallbackNumber"=>nil, "MSRASClientVersion"=>nil, "FramedIPAddress"=>nil, "host"=>"<host>", "NASIdentifier"=>nil, "SessionTimeout"=>nil, "MSAcctAuthType"=>nil, "ProviderName"=>nil, "AcctInterimInterval"=>nil, "type"=>"rras_log", "PolicyName"=>nil, "ServiceType"=>nil, "CalledStationID"=>nil, "NASPortType"=>nil, "ClientIPAddress"=>nil, "ProxyPolicyName"=>"Microsoft Routing and Remote Access Service Policy", "MSMPPEEncryptionTypes"=>nil, "MSRASClientName"=>nil, "RemoteServerAddress"=>nil, "TunnelServerEndpt"=>nil, "TunnelPvtGroupID"=>nil, "ServiceName"=>"RAS", "MSCHAPError"=>nil, "ProviderType"=>"1", "ConnectInfo"=>nil, "AcctTunnelConn"=>nil, "UserName"=>nil, "NASPort"=>nil, "AuthenticationType"=>"4", "MSCHAPDomain"=>nil, "AcctOutputPackets"=>nil, "Time"=>"03:14:17", "AcctInputPackets"=>nil, "PortLimit"=>nil, "CallingStationID"=>nil, "ComputerName"=>"<server>", "AcctTerminateCause"=>nil, "TunnelType"=>nil, "AcctInputOctets"=>nil, "TerminationAction"=>nil, "IdleTimeout"=>nil, "TunnelMediumType"=>nil, "message"=>"\"<server>\",\"RAS\",11/24/2018,03:14:17,3,,\"<user>\",,,,,,,,,,,,,,,,,4,,48,\"311 1 <ip> 05/26/2018 16:09:57 100364\",,,,,,,,,\"100365\",,,,,,,,,,,,,,,,,,,,,,,,,\"Microsoft Routing and Remote Access Service Policy\",1,,,,\r", "NASIPAddress"=>nil, "AcctSessionID"=>"100365", "path"=>"/var/leitura/entrada_vpn_full.csv", "FramedProtocol"=>nil, "TunnelAssignmentID"=>nil, "AcctOutputOctets"=>nil, "MSRASVersion"=>nil, "AcctLinkCount"=>nil, "ReasonCode"=>"48", "AcctDelayTime"=>nil, "Class"=>"311 1 <ip> 05/26/2018 16:09:57 100364"}}
C:/Users/c070054/Downloads/logstash-6.8.6/vendor/bundle/jruby/2.5.0/gems/awesome_print-1.7.0/lib/awesome_print/formatters/base_formatter.rb:31: warning: constant ::Fixnum is deprecated
I can manually put the query " PacketType:1 AND AcctSessionID:100365 AND FQUser:<user>"
on Kibana and I receive the desired result, but I get absolutely NONE of the "Source_" fields on ruby_debug output:
{
"AcctOutputPackets" => nil,
"ProxyPolicyName" => "Microsoft Routing and Remote Access Service Policy",
"AcctLinkCount" => nil,
"AcctInterimInterval" => nil,
"type" => "rras_log",
"AcctTunnelConn" => nil,
"MSRASClientName" => nil,
"RemoteServerAddress" => nil,
"path" => "/var/leitura/entrada_vpn_full.csv",
"EAPFriendlyName" => nil,
"SessionTimeout" => nil,
"MSAcctEAPType" => nil,
"TunnelServerEndpt" => nil,
"PacketType" => "3",
"ServiceType" => nil,
"AcctInputPackets" => nil,
"host" => "<host>",
"TunnelPreference" => nil,
"AuthenticationType" => "4",
"TerminationAction" => nil,
"MSMPPEEncryptionPolicy" => nil,
"ClientVendor" => nil,
"MSAcctAuthType" => nil,
"@metadata" => {
"_type" => "doc",
"total_hits" => 0,
"_index" => "rras_vpn-2018.11.24",
"_id" => "jbDwEGkBOCcFUcpMwgAf",
"fingerprint" => 1014899617
},
"FQUser" => "<user>",
"FramedProtocol" => nil,
"AcctInputOctets" => nil,
"AcctAuthentic" => nil,
"ReasonCode" => "48",
"NASPortType" => nil,
"CallingStationID" => nil,
"EventTimestamp" => nil,
"AcctStatusType" => nil,
"ServiceName" => "RAS",
"PolicyName" => nil,
"CallbackNumber" => nil,
"ComputerName" => "<server>",
"Class" => "311 1 <ip> 05/26/2018 16:09:57 100364",
"ProviderType" => "1",
"TunnelAssignmentID" => nil,
"MSMPPEEncryptionTypes" => nil,
"ConnectInfo" => nil,
"PortLimit" => nil,
"IdleTimeout" => nil,
"Time" => "03:14:17",
"ClientIPAddress" => nil,
"NASIdentifier" => nil,
"CalledStationID" => nil,
"TunnelClientEndpt" => nil,
"AcctDelayTime" => nil,
"@version" => "1",
"MSCHAPDomain" => nil,
"MSRASVendor" => nil,
"ClientFriendlyName" => nil,
"FramedIPAddress" => nil,
"AcctSessionID" => "100365",
"MSRASClientVersion" => nil,
"UserName" => nil,
"TunnelType" => nil,
"AcctSessionTime" => nil,
"NASPort" => nil,
"message" => "\"<server>\",\"RAS\",11/24/2018,03:14:17,3,,\"<user>\",,,,,,,,,,,,,,,,,4,,48,\"311 1 <ip> 05/26/2018 16:09:57 100364\",,,,,,,,,\"100365\",,,,,,,,,,,,,,,,,,,,,,,,,\"Microsoft Routing and Remote Access Service Policy\",1,,,,\r",
"Date" => "11/24/2018",
"TunnelMediumType" => nil,
"AcctMultiSsnID" => nil,
"MSRASVersion" => nil,
"ProviderName" => nil,
"@timestamp" => 2018-11-24T05:14:17.000Z,
"AcctOutputOctets" => nil,
"TunnelPvtGroupID" => nil,
"AcctTerminateCause" => nil,
"NASIPAddress" => nil,
"MSCHAPError" => nil
}
What could I be doing wrong?