I'm trying to figure out how to query Kibana for specific event ID numbers from the dashboard search area the article mentions. Is there a definitive guide for searching OSSEC with Kibana.
Jesus Linares
unread,
Sep 20, 2016, 3:56:44 AM9/20/16
Reply to author
Sign in to reply to author
Forward
Sign in to forward
Delete
You do not have permission to delete messages in this group
Copy link
Report message
Show original message
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
to ossec-list
Hi,
in order to filter by an event ID of Windows, just use this query in the search bar of kibana:
decoder.name:"windows" AND id:"4625"
In this case, you are filtering events with id 4625:
2016Sep2007:50:17WinEvtLog:Security: AUDIT_FAILURE(4625):Microsoft-Windows-Security-Auditing:(no user):no domain: WIN-....:An account failed to log on...
I assume you are sending the file alerts.json to elasticsearch.
Regards.
namobud...@gmail.com
unread,
Sep 21, 2016, 9:55:17 AM9/21/16
Reply to author
Sign in to reply to author
Forward
Sign in to forward
Delete
You do not have permission to delete messages in this group
Copy link
Report message
Show original message
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
to ossec-list
I tried this and it didn't work, I think because decoder.name doesn't exist in the logstash index. Instead of id, I have _id which is not a number but a character string.
Jesus Linares
unread,
Sep 22, 2016, 4:58:38 AM9/22/16
Reply to author
Sign in to reply to author
Forward
Sign in to forward
Delete
You do not have permission to delete messages in this group
Copy link
Report message
Show original message
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
to ossec-list
Hi,
Review alerts.json in order to know if you have the decoder name and the event id extracted in fields. Also, check out your logstash mapping. If the fields are not extracted in alerts.json, you can not filter by them in kibana.
I did the query in Wazuh and it works, so I recommend you to try it. This is the documentation.