I recently blew away my old ELK stack and built a new one. I still maintained the same log sources, Sysmon, Windows events, and Powershell, (using the configuration that came with winlogbeat) but now I cannot filter on event.code which shows up in Kibana with an icon next to it that looks like a triangle with an exclamation point in it. Could someone that has had this experience or knows how to fix it help me through this?
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.