-
Notifications
You must be signed in to change notification settings - Fork 461
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[Question]: 'windows.forwarded' and 'windows.sysmon_operational' dataset logs not available under datastreams page for agent deployed #551
Comments
Pinging @elastic/ingest-management (Team:Ingest Management) |
Reviewed & assigned to @EricDavisX |
@narph can you look at this? Not sure if this is a bug or just the system not having the logs. |
@narph further, anything you want the tem to help re-test - @dikshachauhan-qasource and team can test on more systems or execute certain end-user actions / operations on the host to validate. some of this may be our lack of understanding of how to test it appropriately. |
@dikshachauhan-qasource and Manish says they have some research on applications that can help triggre those datasets. Please do post what you know. And, we can install those applications so long as they aren't malware / malicious. :) |
Yes , a few actions are necessary in order to generate events for both The forwarded events log contains only events collected from remote hosts using the Windows Event Collector. This option is only available on operating systems supporting the Windows Event Log API (Microsoft Windows Vista and newer). There is extensive online documentation that goes over the steps of windows log forwarding, if anyone is interested I can try to expand on that and provide more info here. The
That is interesting, one thing you can quickly check in the Windows Server 2012 is if the event logs are there for
in PowerShell and check for for |
Hi @EricDavisX For sysmon logs, we have researched and found sysmon V13.01 application available on Microsoft Official website. As per our understanding if that application is installed and collecting some logs then we can attempt to validate data for windows.sysmon datasets under Data Streams page. Further, for 'windows.forwarded' logs dataset, we have gone through this article available on Microsoft Official website. It seems hard to validate. Please have a look and provide your feedback on this. Thanks |
hi @dikshachauhan-qasource , I have replied above.
Yes, we also reference https://docs.microsoft.com/en-us/sysinternals/downloads/sysmon in our Winlogbeat docs, if this is missing in the integration documentation we need to update it.
Not sure if you are still testing on the Windows Server 2012 machine but here is some info and steps here: |
Pinging @elastic/integrations (Team:Integrations) |
Hi @narph Today, we have attempted to reproduce the issue on 8.0 snapshot cloud build. However, due to defect #23652, we are blocked. We will revalidate above observation once reported issue is resolved. cc @EricDavisX Thanks |
note- this can be tested on 7.11 latest BC at this point, as the package has been merged to prod. @dikshachauhan-qasource if 7.11 does NOT have the same install problem as 23652 above, please retest there and report back. Thank you. |
Hi @narph As per feedback on #551 (comment) we have re-validated this issue on 8.0.0 Snapshot Kibana Cloud environment with agent installed on Windows Server 2012 . Build details are as follows:
Observations:
Query: cc @EricDavisX Thanks |
Ph and I can throw our brief opinion in, we do not think these are needed for 7.11. 'windows.forwarded' - is this something we want to just skip in manual testing? @narph One thought PH has is that we could list out all of the fields / data_streams and pre-acknowledge which ones are hard to test manually, and will therefore be skipped during manual iterations by the Fleet test team. Further, we could put this as part of the integration package, to make it more clear. Thoughts? |
Closing this issue as will be taken care by Onsite Automation team. |
Kibana version:
8.0 Snapshot Kibana Cloud environment
Host OS and Browser version:
Windows server 2012, All
Preconditions
Steps to reproduce:
Observation
On Windows Server 2012
Following dataset logs not available on DataStream page.
On Windows 10
Following dataset logs not available on DataStream page.
Queries
We have looked for 'Forwardedevents' and 'sysmon' Events in Event viewer in both OSs and could not find them at location:
So as per our understanding, that could be the reason of non-availability for below datastreams
Query 1: Could you please let us know if it is expected or any action is required to be performed to trigger these events.
So that required data sets gets generated on Data stream page.
Query 2: We have observed that only 'windows.powershel' logs dataset was generated for Windows server 2012 OS.
So, do we need to report defect for 'windows.powershell_operational' or it is working as expected.
Screenshots:
The text was updated successfully, but these errors were encountered: