Leave a Reply

10 Comments on "Monitoring Active Directory with ELK"

avatar
  Subscribe  
newest oldest most voted
Notify of
Cesare
Guest

Hello Pablo,
very nice works, I’ll try to take some of your suggestions.
I was testing your config and I just want to advise you that you forgot a “}” to close the else if:
else if [event_data][LogonType] == “9” {
mutate {
add_field => { “Method” => “NewCredentials” }
}

thanks again,
Cesare

Francesco Ferrari
Guest

Pablo, you would mind to share your config files? I´ve tried to make it work but far from it.

Thanks for your attention.