I'm building a proof of concept using ELK + Winlogbeat to provide us with tools analysing data from Windows Event logs.
In this environment I have 2 servers: log server + ELK server
It looks like everything is working.
Events are being sent form the Logserver to ELK. I have an index pattern working...
However I have 2 questions:
- I did have some prior test data in he ELK and I'd pushed the sample dashboards to it. This was so that I could demonstrate the idea to my manager. I have since cleared the old index and created a new one.
However the dashboard are all broken. The index has the same name "Winlogbeat-*"
On the dashboard in Kibana it says "click here to fix" but it's not clickable. So I am totally confused.
- I have many weeks of events in the log ForwardedEvents however the Index is only showing events from a couple of days.
How do I get it to go back further. Note that I have the following entry in my config:
- name: ForwardedEvents
- name: Application
- name: Security
- name: System