I've setup WinLogBeat on Windows server and it ships to the same logstash and the messages are coming through. After doing in-depth troubleshooting, i believe the issue is that auditbeat is sending a messages object instead of a message object. Has anyone else experienced this? Should this be a new ticket in github?
I wanted to check in on this as it has been a week. Is there any other information i can supply or any other validations I should complete before opening a ticket for a bug?
Here is another update. I was able to setup and configure auditd and filebeat. Going this route everything shows up in the s3 bucket as expected. Im not sure if this is a bug in the way auditbeat ships vs how all the other beats ship but i did not change anything in the logstash config.
The default format string for the S3 output plugin includes a reference to the message field, but if the event being pushed does not have a message field, the format string is not expanded.
I'm not familiar with the exact format of AuditBeat, but if you add a Stdout Output Plugin, you may be able to determine the "shape" of the output and coerce it into place:
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.