Hello I'm getting ELK running node in command, that i don't configure, and this string below goes to arcsight:
2022-07-04T12:50:30.046Z {name=TST-FT13} Jul 4 15:50:29 TST-FT13 sshd[1872]: Accepted keyboard-interactive/pam for root from 192.168.11.11 port 58293 ssh2
Now they ask me to remove part that i marked with bold. I`m trying some remove_field variants in filter config, but it not help, please help to find solution.
udp {
id => "arcsight_line"
host => "192.168.99.99"
port => 714
codec => "line"
}
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.