I set some IPS logs into ECS format using Fluentd and then delivered them to elasticsearch.
And you can see that the log is coming in from kibana.
The problem is that Elastic Security's Overview tap doesn't show the number of incoming events in Network events.
It is checked in the events at the top, but the number of events cannot be checked in the host events and network events below.
I'm not going to use beats. However, it seems that you can only check specific equipment events coming to beats.
How can I express the number of events of different equipment?