Hi
I have created one POC setup in ELK for analyzing EMC ISILON storage audit log. I forwarded the log through Syslog server and filebeat is sending the log to logstash. The ISILON was integrated with Windows AD so i am getting audit logs with windows AD users SID but I want to map the SID field with windows user name in ELK. I need help from anyone to fix this issue.
Thanks in Advance