No events found - OpenSearch / Filebeat #219
opoplawski
started this conversation in
General
Replies: 4 comments 1 reply
-
|
Are you using Filebeats Suricata module? |
Beta Was this translation helpful? Give feedback.
0 replies
-
|
No, I'm ingesting the eve.json log:
|
Beta Was this translation helpful? Give feedback.
1 reply
-
|
I switched one of our inputs to the suricata module, but still nothing. |
Beta Was this translation helpful? Give feedback.
0 replies
-
|
Restarted evebox again with different elastic user and we seem to be in business now. |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
We are shipping suricata events from filebeat -> logstash -> opensearch and preserving the filebeat-* index. I think I've configured everything properly:
I'm not seeing any errors/warnings on evebox or opensearch. How can I see what queries are being made?
Beta Was this translation helpful? Give feedback.
All reactions