evtx fields that need to be added to index template #525
Labels
bug
Something isn't working
dashboards
Relating to Malcolm's OpenSearch Dashboards interface
host logs
Related to Malcolm's processing of host logs forwarded from external forwearders
logstash
Relating to Malcolm's use of Logstash
opensearch
Relating to Malcolm's use of OpenSearch
Milestone
Some of the EVTX fields coming from the
evtx
utility need to be normalized. Here's a sanitized version of the output from logstash. The files used are here.The text was updated successfully, but these errors were encountered: