Filebeat module system don't parse auth log

Hello all,

I am using Filebeat 7.12.1 with the system module
The logs send in Elastic without problem, but some failed authentication logs from pam_unix(sshd:auth) are not parsed.
Do you know why?

Thank you very much !

Nobody has any ideas ? :frowning:

