Skip to content

[system] Windows Security - Use Managment Events dashboard missing forwarded events #10431

@nicpenning

Description

@nicpenning

It seems that the windows.forwarded is missing from some visualizations resulting in missing data:

image

Exploring these visuals in discover look something like this:

image

Note that the dataset is set twice. Likely the solution is to remove the search query in the bar with the dataset since it is redundant.

Removing that part of the search filter provides results like so:
image

Metadata

Metadata

Assignees

Labels

Integration:systemSystemTeam:Security-Windows PlatformSecurity Windows Platform team [elastic/sec-windows-platform]bugSomething isn't working, use only for issues

Type

No type
No fields configured for issues without a type.

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions