Join GitHub today
Document all fields used in auditd dashboards #3962
To allow the dashboards to load all fields used in the dashboards need to be in the Kibana index pattern.
I also changed pid, ppid, item, and item to just be keywords. There wasn’t really a good reason reason for these to be stored as numbers and sometimes in the events these were set to characters like “?”.