Lehugo
(Hung Le)
August 10, 2020, 9:06am
1
all the security Events have the the field winlog.keywords but ForwardedEvents don't Forward it.
How can i configure the winlogbeat.yml file that the ForwardedEvents fordward the field winlog.keywords ?
https://www.elastic.co/guide/en/beats/winlogbeat/master/exported-fields-winlog.html
winlog.keywords is required: False
How can i make it true?
Lehugo
(Hung Le)
August 10, 2020, 10:11am
2
Try to use inlude_fields but it doesn' work
name: ForwardedEvents
processors:
- include_fields:
when:
has_fields: ["winlog.computer_name"]
fields: ["winlog.keywords"]
system
(system)
Closed
September 7, 2020, 12:11pm
3
This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.