Replies: 1 comment 1 reply
-
Filebeat is simply an agent -- it reads the files that it's instructed to and then forwards their contents to the Logstash receiver in Security Onion. If you'd like a completely empty Kibana, you could do this: Log into the SSH session on your Manager/Standalone node. That should stop every process that would be writing into Elasticsearch and clear out whatever's in there, so your Kibana will be empty. |
Beta Was this translation helpful? Give feedback.
1 reply
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
Hi, I know I filebeat in my security onion so-status. I am using windows 10. The events get into my kibana, even when i so-elastic-clear and so-nsm-clear. How can I clear filebeat so kibana is completely empty?
thanks for any help, adive or suggestions
Beta Was this translation helpful? Give feedback.
All reactions