No events found - OpenSearch / Filebeat #219
opoplawski
started this conversation in
General
Replies: 4 comments 1 reply
-
Are you using Filebeats Suricata module? |
Beta Was this translation helpful? Give feedback.
0 replies
-
No, I'm ingesting the eve.json log:
|
Beta Was this translation helpful? Give feedback.
1 reply
-
I switched one of our inputs to the suricata module, but still nothing. |
Beta Was this translation helpful? Give feedback.
0 replies
-
Restarted evebox again with different elastic user and we seem to be in business now. |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
We are shipping suricata events from filebeat -> logstash -> opensearch and preserving the filebeat-* index. I think I've configured everything properly:
I'm not seeing any errors/warnings on evebox or opensearch. How can I see what queries are being made?
Beta Was this translation helpful? Give feedback.
All reactions