I am shipping logs from my DC to Logstash and then to Elasticsearch. I am trying to visualize domain user logins to all domain joined servers.
But It is not showing me the name of server on which user logs in. It always shows DC server because that is where authentication is being done. But I am interested to see which user logs on to which server.
Has anyone done anything similar before?