Good afternoon everyone,
I recently blew away my old ELK stack and built a new one. I still maintained the same log sources, Sysmon, Windows events, and Powershell, (using the configuration that came with winlogbeat) but now I cannot filter on event.code which shows up in Kibana with an icon next to it that looks like a triangle with an exclamation point in it. Could someone that has had this experience or knows how to fix it help me through this?
Thank you for your time and help!