Grok for auditbeat log

Hi , I'm trying to set grok for auditbeat pipeline but getting grokparsefailure

maybe someone has a sample audit grok configuration ?

thanks in advance.

You are trying to ingest the log output from Auditbeat? I suggest configuring the Beat to output JSON logs. That should make it easier to parse.

logging.json: true

This topic was automatically closed 21 days after the last reply. New replies are no longer allowed.