Skip to content
Discussion options

You must be logged in to vote

It looks like that rule query is

event.agent_id_status:* and not tags:forwarded

that event.agent_id_status field appears to have an issue open with it when ingesting logs using logstash (Security Onion logs go from agent -> logstash -> redis) elastic/kibana#183959 note the comment elastic/kibana#183959 (comment)

Replies: 2 comments 1 reply

Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
1 reply
@rfuller318
Comment options

Answer selected by rfuller318
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
2.4
Labels
None yet
2 participants