rsyslog-elasticsearch-kibana icon indicating copy to clipboard operation
rsyslog-elasticsearch-kibana copied to clipboard

action field not making it into elasticsearch

Open theWizK opened this issue 7 years ago • 0 comments

Hi there.. I'm trying to search for user logins using the searches / dashboards set up for showing user logins, but I notice that the action field is not making it into elasticsearch. I'm not sure where that field should be getting introduced, but I think possibly it is as part of the normalize rules for the audit log. I don't fully understand how that turns into fields that end up being turned into the $!all-json variable used by the omelasticsearch module. In either case -- the search and dashboard aren't working, I believe because they required the action field to be identified and they never are. I definitely see messages if I search for type=USER_LOGIN. Any help would be appreciated.

theWizK avatar Nov 17 '16 21:11 theWizK