Comments (5)
@ebvjr could try the below configuration:
setup:
template:
name: "testbeat"
pattern: "testbeat*"
ilm:
enabled: true
rollover_alias: "testbeat"
pattern: "{now/d}-000001"
output.elasticsearch:
hosts: ["http://localhost:9200"]
username: "elastic"
password: "changeme"
index: "testbeat-%{[agent.version]}"
This should give a result like testbeat-1.4.3-2020.01.14-000001
Thanks
from o365beat.
Thanks for the issue Eduardo, I'll reproduce it and see if I can track down the problem and get you a resolution. I think all that's handled by libbeat, but perhaps I made a change that affected it without realizing.
Did you run the setup
command against your elastic instance before shipping the logs? Thanks again.
from o365beat.
@ebvjr - was @opendevl's suggestion able to fix your issue? If so, I'll capture it in the docs. Thanks to both of you!
from o365beat.
Yes. thank you!
from o365beat.
Glad to hear it, @ebvjr, and thank you again to @opendevl for the suggested fix. I see how o365beat.reference.yml
led you astray, it suggests including agent.version
in setup.name
and setup.pattern
. Unfortunately that's an artifact of the build process which concatenates libbeat/_meta/config.reference.yml.tmpl
with our o365beat reference template, and we don't control those examples.
I'll mention the fix in the docs, but I don't plan to re-write that libbeat reference template during the build ... there may be other bugs in there that we won't catch, and then we'll have signed up to keep it correct forever 😃. Please feel free to file an issue or PR for the upstream reference template!
Thanks again.
from o365beat.
Related Issues (20)
- Exiting: error loading config file: yaml: line 2: did not find expected node content HOT 5
- Understanding Authentication Data HOT 4
- visualization not working HOT 5
- Client.Timeout for Exchange/General/Sharepoint HOT 6
- Docker Instructions HOT 3
- Parsing Extended Properties HOT 4
- Preventing Duplicate Events HOT 4
- Dashboard and visualizations not working - error with fields.keyword HOT 5
- Logstash connection errors HOT 7
- o365 audit.exchange not returning threat audit logs HOT 3
- WARN beater/o365beat.go:249 start XX must be <=YY hrs ago, resetting HOT 3
- Live Realoding Credentials HOT 2
- Proxy support for the API requests HOT 1
- Certificate signed by unknown authority message HOT 2
- AzureActiveDirectory Logs not pulled HOT 3
- Log content changed recently?
- GCC High no available content locations: HOT 1
- Tenant ID not found
- Does O365beat support multiple Office 365 tenants scenario
- Log file is not getting created
Recommend Projects
-
React
A declarative, efficient, and flexible JavaScript library for building user interfaces.
-
Vue.js
🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
-
Typescript
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
-
TensorFlow
An Open Source Machine Learning Framework for Everyone
-
Django
The Web framework for perfectionists with deadlines.
-
Laravel
A PHP framework for web artisans
-
D3
Bring data to life with SVG, Canvas and HTML. 📊📈🎉
-
Recommend Topics
-
javascript
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
-
web
Some thing interesting about web. New door for the world.
-
server
A server is a program made to process requests and deliver data to clients.
-
Machine learning
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
-
Visualization
Some thing interesting about visualization, use data art
-
Game
Some thing interesting about game, make everyone happy.
Recommend Org
-
Facebook
We are working to build community through open source technology. NB: members must have two-factor auth.
-
Microsoft
Open source projects and samples from Microsoft.
-
Google
Google ❤️ Open Source for everyone.
-
Alibaba
Alibaba Open Source for everyone
-
D3
Data-Driven Documents codes.
-
Tencent
China tencent open source team.
from o365beat.