I'm building a proof of concept using ELK + Winlogbeat to provide us with tools analysing data from Windows Event logs.
In this environment I have 2 servers: log server + ELK server
It looks like everything is working.
Events are being sent form the Logserver to ELK. I have an index pattern working...
However I have 2 questions:
I did have some prior test data in he ELK and I'd pushed the sample dashboards to it. This was so that I could demonstrate the idea to my manager. I have since cleared the old index and created a new one.
However the dashboard are all broken. The index has the same name "Winlogbeat-*"
On the dashboard in Kibana it says "click here to fix" but it's not clickable. So I am totally confused.
I have many weeks of events in the log ForwardedEvents however the Index is only showing events from a couple of days.
How do I get it to go back further. Note that I have the following entry in my config:
Thanks! That appears to have fixed the dashboards.
I'll have to remember to do that in the future. I know it only fixes the sample dashboards (and I have a lot more work to do there) it at least allowed me to get a visualisation of our existing data.
I am still unsure why the data isn't looking correct. Perhaps my Event Forwarding infrastructure has a problem? Who knows I can at least see there's an issue!
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.