I got a very strange problem. We installed winlogbeat v7.2 and directly shipped windows event log to ES, configurations about winlogbeat as below:
- name: Security
- name: Microsoft-Windows-NTLM/Operational
The logs shipped to ES but for Winlogbeat security channel ,the @timestamp was before the actually event create time ,however the @timestamp of Microsoft-Windows-NTLM/Operational was correct. Outputs from ES as below: 1.for security channel:
2.for NTLM channel:
Can someone else help me . This issue make me crazy....