My Problem is, that there are two Logon ID's and Kibana is using the first one to be a field, but I need the second one for filtering. What can I do? Do I have to change the mapping in ElasticSearch? I'm new to the ELK-Stack. =)
Hello,
What are you using to ingest the Windows Event Logs in kibana? There might be a way to filter that ID out in order to have it as a separate field for you.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.