Logstash error on 2.3.170 #9087
Replies: 1 comment 3 replies
-
Please provide more information. Is this coming from a Windows machine? If so, how are the logs getting from that Windows machine to your Security Onion deployment? |
Beta Was this translation helpful? Give feedback.
3 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
Logstash error on 2.3.170
"reason"=>"failed to parse field [winlog.event_data.param1] of type [date] in document with id 'xxx'. Preview of field's value: 'Service stopped'", "caused_by"=>{"type"=>"illegal_argument_exception", "reason"=>"failed to parse date field [Service stopped] with format [strict_date_optional_time||epoch_millis]", "caused_by"=>{"type"=>"date_time_parse_exception", "reason"=>"Failed to parse with all enclosed parsers
Beta Was this translation helpful? Give feedback.
All reactions