Skip to content

Filebeat system visualisation do not use ECS #11859

@fkelbert

Description

@fkelbert

With 7.0, some Filebeat system visualisation do not work, as they do not use proper ECS fields.

Specifically the visualisation:

  • SSH users of failed login attempts [Filebeat System] ECS
  • Successful SSH logins
  • SSH login attempts

These visualisations should filter on field system.auth.ssh.event rather than event.action.

Metadata

Metadata

Assignees

Type

No type
No fields configured for issues without a type.

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions