New to ELK and trying to get this working. I have successfully installed 6.8.3, and it worked i was getting the correct fields from filebeat including the fileset.module information. but i ended up upgrading to 7.3.2 and now im unable to get this data from filebeat, its just hitting logstash and going to elasticsearch as syslog data (completely bypassing the stock filter since its not showing the fileset.module field)
I've been beating my head on this and have completely wiped out all the instances of filebeat, recreated, tried removing and re creating templates, etc. nothing seems to be changing out this data is being sent. I have another filter that is working file (for a fortinet firewall) it seems that all of my issues are specifically because filebeat isnt sending the correct metadata. is there somewhere to enable or disable this??
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.