Just set up a Wec server to forward windows event logs to my elk stack via the setup powershell script. We were successful in the command running, but now we're receiving the logs. I just can't view them in Discover and I'm getting some errors I'll post below. The health of the index is Yellow.
This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.