Hello,
I noticed the windows_rare_user_type10_remote_login ml job didn't produce a lot of data anymore.. To be sure there was nothing going on with an outdated builtin configuration, I re-added this ml job with the provided wizard.
But again the ml job did not produce any data. So I checked the query and noticed the event.type value in the query still points to an older value:
{"bool":{"filter":[{"term":{"event.type":"authentication_success"}},{"term":{"winlog.event_data.LogonType":"10"}},{"term":{"agent.type":"winlogbeat"}}]}}
event.type
for type 10 RDP events is now start
This might already be fixed in 7.11, but I don't have a 7.11 cluster yet (ad bug...), so I can't check.
Grtz
Willem