Filebeat 7.10 aws cloudtrail is not parsing the output as shown in documentation


I have configured aws clodutrail module using filebeat to push the logs to Elasticsearch. Logs are pushed to the elk. But am facing two issues.

  1. Messages are showing in string instead of json
  2. If i used processor and changed message to string. But the dashboard for cloudtrail is not satisfied with default ingest grok pattern.
    Please help me to view the output in dashboard.

Can u show what ur getting? The original message should be in event.original. Can you show any errors or log messages from Filebeat?

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.