Hi @andrewkroh, Thanks again for your help. Just need some help in finding my feet with all of this.
All have "@timestamp": "2018-02-28T14:08:20.804Z",
Message 1
{
"_index": "auditbeat-6.2.2-2018.02.28",
"_type": "logs",
"_id": "AWHcvhsql410dLnM6zqn",
"_version": 1,
"_score": null,
"_source": {
"process": {
"name": "ntpd",
"pid": "16097",
"exe": "/usr/sbin/ntpd",
"ppid": "1"
},
"@timestamp": "2018-02-28T14:08:20.804Z",
"beat": {
"name": "ptc-desk",
"hostname": "soptct61-01.hursley.ibm.com",
"version": "6.2.2"
},
"@version": "1",
"host": "soptct61-01.hursley.ibm.com",
"auditd": {
"summary": {
"actor": {
"secondary": "ntp",
"primary": "nhopper"
},
"how": "/usr/sbin/ntpd"
},
"result": "success",
"sequence": 38316124,
"data": {
"a1": "7fff4468f400",
"syscall": "select",
"a2": "0",
"exit": "1",
"a3": "0",
"tty": "(none)",
"arch": "x86_64",
"items": "0",
"a0": "18"
},
"session": "8675"
},
"event": {
"action": "",
"category": "audit-rule",
"type": "syscall",
"module": "auditd"
},
"user": {
"fsuid": "38",
"uid": "38",
"name_map": {
"fsuid": "ntp",
"uid": "ntp",
"egid": "ntp",
"auid": "nhopper",
"gid": "ntp",
"euid": "ntp",
"fsgid": "ntp",
"sgid": "ntp",
"suid": "ntp"
},
"auid": "507",
"egid": "38",
"gid": "38",
"euid": "38",
"fsgid": "38",
"sgid": "38",
"suid": "38"
},
"tags": [
"b64_call",
"beats_input_raw_event",
"_grokparsefailure"
]
},
"fields": {
"@timestamp": [
1519826900804
]
},
"sort": [
1519826900804
]
}
Message 2
{
"_index": "auditbeat-6.2.2-2018.02.28",
"_type": "logs",
"_id": "AWHcvhsql410dLnM6zqp",
"_version": 1,
"_score": null,
"_source": {
"process": {
"name": "ntpd",
"pid": "16097",
"exe": "/usr/sbin/ntpd",
"ppid": "1"
},
"@timestamp": "2018-02-28T14:08:20.804Z",
"beat": {
"name": "ptc-desk",
"hostname": "soptct61-01.hursley.ibm.com",
"version": "6.2.2"
},
"@version": "1",
"host": "soptct61-01.hursley.ibm.com",
"auditd": {
"summary": {
"actor": {
"secondary": "ntp",
"primary": "nhopper"
},
"how": "/usr/sbin/ntpd",
"object": {
"type": "socket"
}
},
"result": "fail",
"sequence": 38316126,
"data": {
"a1": "7fff4468f480",
"syscall": "recvmsg",
"exit": "EAGAIN",
"a2": "0",
"a3": "0",
"tty": "(none)",
"arch": "x86_64",
"items": "0",
"a0": "13"
},
"session": "8675"
},
"event": {
"action": "received-from",
"category": "audit-rule",
"type": "syscall",
"module": "auditd"
},
"user": {
"fsuid": "38",
"uid": "38",
"auid": "507",
"egid": "38",
"name_map": {
"fsuid": "ntp",
"uid": "ntp",
"auid": "nhopper",
"egid": "ntp",
"gid": "ntp",
"euid": "ntp",
"fsgid": "ntp",
"sgid": "ntp",
"suid": "ntp"
},
"gid": "38",
"euid": "38",
"fsgid": "38",
"sgid": "38",
"suid": "38"
},
"tags": [
"b64_call",
"beats_input_raw_event",
"_grokparsefailure"
]
},
"fields": {
"@timestamp": [
1519826900804
]
},
"sort": [
1519826900804
]
}
Message 3
{
"_index": "auditbeat-6.2.2-2018.02.28",
"_type": "logs",
"_id": "AWHcvhsql410dLnM6zqo",
"_version": 1,
"_score": null,
"_source": {
"process": {
"name": "ntpd",
"pid": "16097",
"exe": "/usr/sbin/ntpd",
"ppid": "1"
},
"@timestamp": "2018-02-28T14:08:20.804Z",
"beat": {
"name": "ptc-desk",
"hostname": "soptct61-01.hursley.ibm.com",
"version": "6.2.2"
},
"@version": "1",
"host": "soptct61-01.hursley.ibm.com",
"source": {
"port": "123",
"ip": "85.199.214.101"
},
"auditd": {
"result": "success",
"summary": {
"actor": {
"secondary": "ntp",
"primary": "nhopper"
},
"how": "/usr/sbin/ntpd",
"object": {
"secondary": "123",
"type": "socket",
"primary": "85.199.214.101"
}
},
"sequence": 38316125,
"data": {
"a1": "7fff4468f480",
"syscall": "recvmsg",
"a2": "0",
"exit": "48",
"a3": "0",
"tty": "(none)",
"socket": {
"family": "ipv4",
"addr": "85.199.214.101",
"port": "123"
},
"arch": "x86_64",
"a0": "13"
},
"session": "8675"
},
"event": {
"action": "received-from",
"category": "audit-rule",
"type": "syscall",
"module": "auditd"
},
"user": {
"fsuid": "38",
"uid": "38",
"egid": "38",
"name_map": {
"fsuid": "ntp",
"uid": "ntp",
"egid": "ntp",
"auid": "nhopper",
"gid": "ntp",
"euid": "ntp",
"fsgid": "ntp",
"sgid": "ntp",
"suid": "ntp"
},
"auid": "507",
"gid": "38",
"euid": "38",
"fsgid": "38",
"sgid": "38",
"suid": "38"
},
"network": {
"direction": "incoming"
},
"tags": [
"b64_call",
"beats_input_raw_event",
"_grokparsefailure"
]
},
"fields": {
"@timestamp": [
1519826900804
]
},
"sort": [
1519826900804
]
}