Am trying to view the
Filebeat System New user and groups dashboard but the results are sporadic at best.
Filebeat 7.2.0 installed locally on ES instance and on remote machine to confirm. Configured to harvest /var/log/secure
Add a user and watch in Discovery and the event(s) get shipped quickly (filebeat -e -d "*") but the event may or may not turn up either in the dashboard or Discovery. Maybe an hour later but sometimes nothing.
Clean install with no load on the machine (this is the only input configured to check performance)
shows the document arrives within a few seconds but again the Discovery does not reflect this.
Is there a default post process slowing things down before it becomes available? The syslog message log seems to be available without any delay just the auth.