-
Notifications
You must be signed in to change notification settings - Fork 4.9k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Unable to filter winlogbeats events by keywords field #2237
Comments
Try |
I tried it, with this, there is error in log: unexpected type []string |
@andrewkroh Not sure if this could be related to #2209 ? |
There is no more info in log. Just repeated "WARN unexpected type []string in contains condition as it accepts only strings." line. |
In the event log record, And like @spacewander said, it should be configured as |
I opened PR #2248 to make |
This should be fixed in 5.0. |
Version: v5.0.0-alpha5
Operating System: Windows Server 2012R2
I am unable to exclude events by keywords field. Config option " keywords: "Audit Success" " does not work, in beats log is:
Config option " keywords: ["Audit Success"] " also does not work but there is no error in beats log.
Processors config:
The text was updated successfully, but these errors were encountered: