With 7.0, some Filebeat system visualisation do not work, as they do not use proper ECS fields.
Specifically the visualisation:
- SSH users of failed login attempts [Filebeat System] ECS
- Successful SSH logins
- SSH login attempts
These visualisations should filter on field system.auth.ssh.event rather than event.action.
With 7.0, some Filebeat system visualisation do not work, as they do not use proper ECS fields.
Specifically the visualisation:
These visualisations should filter on field
system.auth.ssh.eventrather thanevent.action.