I am new to Winlogbeat and would like to know how to match Event ID, Knowledge Base DB (https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx) with winlogbeat
Thanks.
I am new to Winlogbeat and would like to know how to match Event ID, Knowledge Base DB (https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx) with winlogbeat
Thanks.
You'd need to build a table and then use the translate filter in LS - https://www.elastic.co/guide/en/logstash/current/plugins-filters-translate.html
© 2020. All Rights Reserved - Elasticsearch
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant logo are trademarks of the Apache Software Foundation in the United States and/or other countries.