I am currently in the module “SIEM Visualization Example 4: Users added or removed from a local group (within a specific time period)” and I need to have the following configuration in elastic. The problem is that I’m not getting any results and I think the settings are fine. Could someone correct me?
My conf:
filters: “event.code: is one of 4732, 4733” “group.name: administrators”
rows: username.keyword / winglog.event_data.MemberSid.keyword / group.name.keyword / event.action.keyword / host.name.keyword
PS: I can’t post images of the configuration because I am a new user on the forum.