Hi people. I have an ELK server 7.8.0 running OK in testing mode.
I've configured Logstash to listen on UDP/514 for incoming syslog remote events, Logstash doesn't apply ani filter, just pass the input to Elasticsearch. I've create a new custom index called syslog-network-"YYYYMMDD".
When I go to KIbana's Discover section, I can see these type of log (it's just a sample):
When I go to Kibana's SIEM access link, and after that I go to Events section I can't see the syslog events at all (I've created a custom dashboard looking into my custom index and I can see aprox. 50 millons syslog events by day).
This is my Events panel from SIEM, and it doesn't show any syslog event at all, and syslog events are greater than netflow events:
How can I include the custom index in the events panel from SIEM section of Kibana?
Every time I create a custom index, do I have to do any special task/action ? Because I only create an index pattern for each of them, no more actions I take.
Thanks a lot and regards !!!