2. Create a new visualization. For this, I recommend using a Data Table. Select the index wazuh-alerts-3.x-*.
4. Then select in Aggregations the type Terms and choose the field of the alert you are going to want to see in the Dashboard. From the alert description you shared, we could get the field data.win.system.message to get the following information: "Retry of Backup job 'FULL-QNAP-451' finished with Failed.". For further information, we could add the field data.win.eventdata.data. adding this field into a new sub-bucket.
5. Be careful with the Size of the bucket field, when adding a new sub-bucket, it multiplies the total amount of buckets size used. Using a Size of 10 in the first bucket and a size of 10 in the sub-bucket, will cost 100 buckets in total. The total number of buckets allowed by elasticsearch is 10000 in the latest 7.4 version.
6. Save your visualization
Once you have your visualization created, go to the Dashboard section and create a new Dashboard.
Then Add the visualization created previously and save it. From there, you should be able to check all the fields added in the buckets of the visualization.
I hope it helps. Let me know if you need anything.
Best Regards,
Jose Manuel Lopez
--
You received this message because you are subscribed to a topic in the Google Groups "Wazuh mailing list" group.
To unsubscribe from this topic, visit https://groups.google.com/d/topic/wazuh/IH0XlsML1Q4/unsubscribe.
To unsubscribe from this group and all its topics, send an email to wazuh+un...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/323750d9-e991-4353-b949-5569fbf30cd4%40googlegroups.com.
To unsubscribe from this group and all its topics, send an email to wazuh+unsubscribe@googlegroups.com.