-
Notifications
You must be signed in to change notification settings - Fork 4.9k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[Winlogbeat] Additional Dashboards #14149
Comments
Since winlogbeat is not using any module I am facing a little issue regarding
However, winlogbeat has no module and running I used the Kibana saved objects |
Pinging @elastic/siem (Team:SIEM) |
I think as of today it will make more sense to create an own app inside the SIEM for users and groups, which includes such said details. |
Hi @philippkahr , I would like to ask you if you can share this dashboards? The mentioned link is not functional anymore. Thank you very much in advance |
Hi,
I created some dashboards for active directory audit. There are some rules that have to be applied inside the active directory.
In the pictures shown for the dashboards, I had to insert some mockup values, but I hope you get the idea.
[Winlogbeat] LDAP Insights
Needs https://blogs.technet.microsoft.com/russellt/2016/01/13/identifying-clear-text-ldap-binds-to-your-dcs/ to work. It will write the LDAP information into the windows event log
Directory Service
, so that needs to be added to the Winlogbeat configuration.Dashboards
[Winlogbeat] Active directory group audit
Needs the group audit GPOs to be applied in the Active Directory. They will be written into the
Security
event log.Dashboards
[Winlogbeat] Overview single host
Just a simple alteration of the Winlogbeat Dashboard, just for a single host.
Dashboards
The text was updated successfully, but these errors were encountered: