I am struggling a little bit with the learning curve of Elasticsearch; in the first instance I’d just like to index some specific Windows logs for our privilege management solution and graph out a few metrics.
I’ve got an Elastic stack running on Docker, configured Logstash and winlogbeat to get some data into elasticsearch okay. I’m struggling at the point where I need to break down the resulting table into something more meaningful. The event contents have been broken down into parameters as below. However I’m not sure how to rename these fields now and filter out any that I might not want to store:
I’ve tried putting the winlogbeat through logstash but the output seems to be the same. I’ve tried to find a solution in Elastic’s documentation but I’m not sure where to start!
The University of Derby has a published policy regarding email and reserves the right to monitor email traffic.
If you believe this was sent to you in error, please reply to the sender and let them know.
Key University contacts: http://www.derby.ac.uk/its/contacts/
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.