Surprisingly my elastic version 7.15 with basic license have installed the fleet server and then configured windows-policy with elastic-endpoint and windows integration. Have enabled all the rules; however I am not seeing any logs security app.
Have added windows agent on my Domain controller as well as ADC but still not seeing any logs.
Any clue why? Plus I am seeing below logs in kibana.log
{"type":"log","@timestamp":"2021-10-07T22:43:49+05:30","tags":["info","plugins","securitySolution"],"pid":1102,"message":"[+] Finished indexing 0 signals searched between date ranges [\n {\n \"to\": \"2021-10-07T17:13:49.667Z\",\n \"from\": \"2021-10-07T17:04:49.667Z\",\n \"maxSignals\": 100\n }\n] name: \"SystemKey Access via Command Line\" id: \"c2c1fbc1-229f-11ec-803f-17c1b2345c64\" rule id: \"d75991f2-b989-419d-b797-ac1e54ec2d61\" signals index: \".siem-signals-default\""}
{"type":"log","@timestamp":"2021-10-07T22:43:49+05:30","tags":["error","plugins","securitySolution"],"pid":1102,"message":"An error occurred during rule execution: message: \"index_not_found_exception: [verification_exception] Reason: Found 1 problem\nline -1:-1: Unknown index [*,-*]\" name: \"Clearing Windows Event Logs\" id: \"c2c1fbd5-229f-11ec-803f-17c1b2345c64\" rule id: \"d331bbe2-6db4-4941-80a5-8270db72eb61\" signals index: \".siem-signals-default\""}
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.