Leave a Reply

6 Comments on "Monitoring Active Directory with ELK"

avatar
  Subscribe  
newest oldest most voted
Notify of
Cesare
Guest

Hello Pablo,
very nice works, I’ll try to take some of your suggestions.
I was testing your config and I just want to advise you that you forgot a “}” to close the else if:
else if [event_data][LogonType] == “9” {
mutate {
add_field => { “Method” => “NewCredentials” }
}

thanks again,
Cesare

Francesco Ferrari
Guest

Pablo, you would mind to share your config files? I´ve tried to make it work but far from it.

Thanks for your attention.