Danke bigdani2k Jetzt kommen ne Menge Daten
Ein Fehler war noch Protokoll - UDP statt TCP
Ich sehe auch viele logs der AP's - allerdings als "decoder.name" - "symantec-av"
Code
{
"_index": "wazuh-archives-4.x-2024.11.22",
"_id": "UKbRU5MBlusTOxI81L8h",
"_version": 1,
"_score": null,
"_source": {
"predecoder": {
"hostname": "APLOG",
"timestamp": "Nov 22 13:21:16"
},
"agent": {
"name": "lplog01",
"id": "000"
},
"manager": {
"name": "lplog01"
},
"decoder": {
"name": "symantec-av"
},
"full_log": "Nov 22 13:21:16 APLOG 602232451058,U6-Lite-6.6.78+15404: kernel: [66341.027531] ra0: total mc2uc sta_cnt[1] pending[0] unknown_free[0] accu[0] !",
"input": {
"type": "log"
},
"@timestamp": "2024-11-22T12:21:16.654Z",
"location": "192.168.10.4",
"id": "1732278076.894384",
"timestamp": "2024-11-22T13:21:16.654+0100"
},
"fields": {
"@timestamp": [
"2024-11-22T12:21:16.654Z"
],
"timestamp": [
"2024-11-22T12:21:16.654Z"
]
},
"highlight": {
"decoder.name": [
"@opensearch-dashboards-highlighted-field@symantec-av@/opensearch-dashboards-highlighted-field@"
],
"predecoder.hostname": [
"@opensearch-dashboards-highlighted-field@APLOG@/opensearch-dashboards-highlighted-field@"
]
},
"sort": [
1732278076654
]
}
Alles anzeigen