LME
LME copied to clipboard
Update winlogbeat templates, add info for adding filters
๐ฃ Description
- added winlogbeat 8.5.0 templates into Elastic pipeline
- added instructions on how to add filters to panels on dashboards
๐ญ Motivation and context
1.This change is required because earlier versions of Winlogbeat did the parsing and mapping of logs and this version no longer does that. 2. LME logs many activities that may not be interesting to the user so filtering gives them away to keep them out of the dashboards.
We now will be able to leverage Elastic Common Schema field names.
Closes #155 Closes #57
๐ท Screenshots (DELETE IF UNAPPLICABLE)
๐งช Testing
The API tests were run and a change needed to be made to reflect the updated fields.
The dashboards need to be revisited to make sure they read the new fields.
โ Pre-approval checklist
- [x] Changes are limited to a single goal AND the title reflects this in a clear human readable format
- [ ] Issue that this PR solves has been selected in the Development section
- [ ] I have read and agree to LME's CONTRIBUTING.md document.
- [ ] The PR adheres to LME's requirements in RELEASES.md
- [ ] These code changes follow cisagov code standards.
- [ ] All relevant repo and/or project documentation has been updated to reflect the changes in this PR.
โ Pre-merge Checklist
- [ ] All tests pass
- [ ] PR has been tested and the documentation for testing is above
- [ ] Squash and merge all commits into one PR level commit
โ Post-merge Checklist
- [ ] Delete the branch to keep down number of branches
We will want to update our installers to install these versions before releasing this. The pipeline should fail tests before we start the modification, and pass tests when we finish.