Okay thank you for help, just logged in and found out that I can now verify the Logs with absolutely doing nothing haha I can now verify the incoming logs
Code: Select all
{:timestamp=>"2019-01-01T01:20:40.607000+0800", :message=>"Connection refused (Connection refused)", :class=>"Manticore::SocketException", :level=>:error}
{:timestamp=>"2019-01-01T01:20:40.630000+0800", :message=>"Connection refused (Connection refused)", :class=>"Manticore::SocketException", :level=>:error}
{:timestamp=>"2019-01-01T01:20:40.644000+0800", :message=>"Connection refused (Connection refused)", :class=>"Manticore::SocketException", :level=>:error}
{:timestamp=>"2019-01-01T01:20:40.654000+0800", :message=>"Connection refused (Connection refused)", :class=>"Manticore::SocketException", :level=>:error}
{:timestamp=>"2019-01-01T01:20:40.749000+0800", :message=>"Pipeline main started"}
{:timestamp=>"2019-01-01T01:20:41.154000+0800", :message=>"Attempted to send a bulk request to Elasticsearch configured at '[\"http://localhost:9200\"]', but Elasticsearch appears to be unreachable or down!", :error_message=>"Connection refused (Connection refused)", :class=>"Manticore::SocketException", :level=>:error}
{:timestamp=>"2019-01-01T01:34:20.715000+0800", :message=>"Failed action. ", :status=>400, :action=>["index", {:_id=>nil, :_index=>"logstash-2018.12.31", :_type=>"eventlog", :_routing=>nil}, #<LogStash::Event:0x4cbde227 @metadata_accessors=#<LogStash::Util::Accessors:0x6629f031 @store={}, @lut={}>, @cancelled=false, @data={"EventTime"=>"2018-12-31 17:34:14", "Hostname"=>" -RAV01", "Keywords"=>4611686018427387904, "EventType"=>"WARNING", "SeverityValue"=>3, "Severity"=>"WARNING", "EventID"=>226, "SourceName"=>"Microsoft-Windows-RemoteDesktopServices-RdpCoreTS", "ProviderGuid"=>"{1139C61B-B549-4251-8ED3-27250A1EDEC8}", "Version"=>0, "Task"=>4, "OpcodeValue"=>19, "RecordNumber"=>6350, "ActivityID"=>"{F420E538-D917-40F2-BA1C-E87C50170000}", "ProcessID"=>868, "ThreadID"=>6552, "Channel"=>"Microsoft-Windows-RemoteDesktopServices-RdpCoreTS/Operational", "Domain"=>"NT AUTHORITY", "AccountName"=>"NETWORK SERVICE", "UserID"=>"S-1-5-20", "AccountType"=>"Well Known Group", "Category"=>"RemoteFX module", "Opcode"=>"Runtime", "StateTransition"=>"RDP_TCP", "PreviousState"=>"23", "PreviousStateName"=>"StateUnknown", "NewState"=>"21", "NewStateName"=>"StateDisconnected", "Event"=>"43", "EventName"=>"Event_Disconnect", "ErrorCode"=>"0x80070040", "EventReceivedTime"=>"2018-12-31 17:34:15", "SourceModuleName"=>"eventlog", "SourceModuleType"=>"im_msvistalog", "message"=>"RDP_TCP: An error was encountered when transitioning from StateUnknown in response to Event_Disconnect (error code 0x80070040).", "@version"=>"1", "@timestamp"=>"2018-12-31T17:34:20.208Z", "host"=>"10.109.196.135", "port"=>52025, "type"=>"eventlog"}, @metadata={}, @accessors=#<LogStash::Util::Accessors:0x2dd5366 @store={"EventTime"=>"2018-12-31 17:34:14", "Hostname"=>" -RAV01", "Keywords"=>4611686018427387904, "EventType"=>"WARNING", "SeverityValue"=>3, "Severity"=>"WARNING", "EventID"=>226, "SourceName"=>"Microsoft-Windows-RemoteDesktopServices-RdpCoreTS", "ProviderGuid"=>"{1139C61B-B549-4251-8ED3-27250A1EDEC8}", "Version"=>0, "Task"=>4, "OpcodeValue"=>19, "RecordNumber"=>6350, "ActivityID"=>"{F420E538-D917-40F2-BA1C-E87C50170000}", "ProcessID"=>868, "ThreadID"=>6552, "Channel"=>"Microsoft-Windows-RemoteDesktopServices-RdpCoreTS/Operational", "Domain"=>"NT AUTHORITY", "AccountName"=>"NETWORK SERVICE", "UserID"=>"S-1-5-20", "AccountType"=>"Well Known Group", "Category"=>"RemoteFX module", "Opcode"=>"Runtime", "StateTransition"=>"RDP_TCP", "PreviousState"=>"23", "PreviousStateName"=>"StateUnknown", "NewState"=>"21", "NewStateName"=>"StateDisconnected", "Event"=>"43", "EventName"=>"Event_Disconnect", "ErrorCode"=>"0x80070040", "EventReceivedTime"=>"2018-12-31 17:34:15", "SourceModuleName"=>"eventlog", "SourceModuleType"=>"im_msvistalog", "message"=>"RDP_TCP: An error was encountered when transitioning from StateUnknown in response to Event_Disconnect (error code 0x80070040).", "@version"=>"1", "@timestamp"=>"2018-12-31T17:34:20.208Z", "host"=>"10.109.196.135", "port"=>52025, "type"=>"eventlog"}, @lut={"type"=>[{"EventTime"=>"2018-12-31 17:34:14", "Hostname"=>" -RAV01", "Keywords"=>4611686018427387904, "EventType"=>"WARNING", "SeverityValue"=>3, "Severity"=>"WARNING", "EventID"=>226, "SourceName"=>"Microsoft-Windows-RemoteDesktopServices-RdpCoreTS", "ProviderGuid"=>"{1139C61B-B549-4251-8ED3-27250A1EDEC8}", "Version"=>0, "Task"=>4, "OpcodeValue"=>19, "RecordNumber"=>6350, "ActivityID"=>"{F420E538-D917-40F2-BA1C-E87C50170000}", "ProcessID"=>868, "ThreadID"=>6552, "Channel"=>"Microsoft-Windows-RemoteDesktopServices-RdpCoreTS/Operational", "Domain"=>"NT AUTHORITY", "AccountName"=>"NETWORK SERVICE", "UserID"=>"S-1-5-20", "AccountType"=>"Well Known Group", "Category"=>"RemoteFX module", "Opcode"=>"Runtime", "StateTransition"=>"RDP_TCP", "PreviousState"=>"23", "PreviousStateName"=>"StateUnknown", "NewState"=>"21", "NewStateName"=>"StateDisconnected", "Event"=>"43", "EventName"=>"Event_Disconnect", "ErrorCode"=>"0x80070040", "EventReceivedTime"=>"2018-12-31 17:34:15", "SourceModuleName"=>"eventlog", "SourceModuleType"=>"im_msvistalog", "message"=>"RDP_TCP: An error was encountered when transitioning from StateUnknown in response to Event_Disconnect (error code 0x80070040).", "@version"=>"1", "@timestamp"=>"2018-12-31T17:34:20.208Z", "host"=>"10.109.196.135", "port"=>52025, "type"=>"eventlog"}, "type"], "[program]"=>[{"EventTime"=>"2018-12-31 17:34:14", "Hostname"=>" -RAV01", "Keywords"=>4611686018427387904, "EventType"=>"WARNING", "SeverityValue"=>3, "Severity"=>"WARNING", "EventID"=>226, "SourceName"=>"Microsoft-Windows-RemoteDesktopServices-RdpCoreTS", "ProviderGuid"=>"{1139C61B-B549-4251-8ED3-27250A1EDEC8}", "Version"=>0, "Task"=>4, "OpcodeValue"=>19, "RecordNumber"=>6350, "ActivityID"=>"{F420E538-D917-40F2-BA1C-E87C50170000}", "ProcessID"=>868, "ThreadID"=>6552, "Channel"=>"Microsoft-Windows-RemoteDesktopServices-RdpCoreTS/Operational", "Domain"=>"NT AUTHORITY", "AccountName"=>"NETWORK SERVICE", "UserID"=>"S-1-5-20", "AccountType"=>"Well Known Group", "Category"=>"RemoteFX module", "Opcode"=>"Runtime", "StateTransition"=>"RDP_TCP", "PreviousState"=>"23", "PreviousStateName"=>"StateUnknown", "NewState"=>"21", "NewStateName"=>"StateDisconnected", "Event"=>"43", "EventName"=>"Event_Disconnect", "ErrorCode"=>"0x80070040", "EventReceivedTime"=>"2018-12-31 17:34:15", "SourceModuleName"=>"eventlog", "SourceModuleType"=>"im_msvistalog", "message"=>"RDP_TCP: An error was encountered when transitioning from StateUnknown in response to Event_Disconnect (error code 0x80070040).", "@version"=>"1", "@timestamp"=>"2018-12-31T17:34:20.208Z", "host"=>"10.109.196.135", "port"=>52025, "type"=>"eventlog"}, "program"], "[host]"=>[{"EventTime"=>"2018-12-31 17:34:14", "Hostname"=>" -RAV01", "Keywords"=>4611686018427387904, "EventType"=>"WARNING", "SeverityValue"=>3, "Severity"=>"WARNING", "EventID"=>226, "SourceName"=>"Microsoft-Windows-RemoteDesktopServices-RdpCoreTS", "ProviderGuid"=>"{1139C61B-B549-4251-8ED3-27250A1EDEC8}", "Version"=>0, "Task"=>4, "OpcodeValue"=>19, "RecordNumber"=>6350, "ActivityID"=>"{F420E538-D917-40F2-BA1C-E87C50170000}", "ProcessID"=>868, "ThreadID"=>6552, "Channel"=>"Microsoft-Windows-RemoteDesktopServices-RdpCoreTS/Operational", "Domain"=>"NT AUTHORITY", "AccountName"=>"NETWORK SERVICE", "UserID"=>"S-1-5-20", "AccountType"=>"Well Known Group", "Category"=>"RemoteFX module", "Opcode"=>"Runtime", "StateTransition"=>"RDP_TCP", "PreviousState"=>"23", "PreviousStateName"=>"StateUnknown", "NewState"=>"21", "NewStateName"=>"StateDisconnected", "Event"=>"43", "EventName"=>"Event_Disconnect", "ErrorCode"=>"0x80070040", "EventReceivedTime"=>"2018-12-31 17:34:15", "SourceModuleName"=>"eventlog", "SourceModuleType"=>"im_msvistalog", "message"=>"RDP_TCP: An error was encountered when transitioning from StateUnknown in response to Event_Disconnect (error code 0x80070040).", "@version"=>"1", "@timestamp"=>"2018-12-31T17:34:20.208Z", "host"=>"10.109.196.135", "port"=>52025, "type"=>"eventlog"}, "host"]}>>], :response=>{"create"=>{"_index"=>"logstash-2018.12.31", "_type"=>"eventlog", "_id"=>"AWgFVKgSBNPXRS-PpM6U", "status"=>400, "error"=>"MapperParsingException[failed to parse [ErrorCode]]; nested: NumberFormatException[For input string: \"0x80070040\"]; "}}, :level=>:warn}
{:timestamp=>"2019-01-01T02:10:18.353000+0800", :message=>"Failed action. ", :status=>400, :action=>["index", {:_id=>nil, :_index=>"logstash-2018.12.31", :_type=>"eventlog", :_routing=>nil}, #<LogStash::Event:0x6c46643d @metadata_accessors=#<LogStash::Util::Accessors:0x7d5ab20f @store={}, @lut={}>, @cancelled=false, @data={"EventTime"=>"2018-12-31 18:09:34", "Hostname"=>" -RBKP01", "Keywords"=>4611686018427387904, "EventType"=>"WARNING", "SeverityValue"=>3, "Severity"=>"WARNING", "EventID"=>226, "SourceName"=>"Microsoft-Windows-RemoteDesktopServices-RdpCoreTS", "ProviderGuid"=>"{1139C61B-B549-4251-8ED3-27250A1EDEC8}", "Version"=>0, "Task"=>4, "OpcodeValue"=>19, "RecordNumber"=>6933, "ActivityID"=>"{F420C7FE-459B-4921-98C1-D356D0570000}", "ProcessID"=>984, "ThreadID"=>10824, "Channel"=>"Microsoft-Windows-RemoteDesktopServices-RdpCoreTS/Operational", "Domain"=>"NT AUTHORITY", "AccountName"=>"NETWORK SERVICE", "UserID"=>"S-1-5-20", "AccountType"=>"Well Known Group", "Category"=>"RemoteFX module", "Opcode"=>"Runtime", "StateTransition"=>"RDP_SEC", "PreviousState"=>"0", "PreviousStateName"=>"FStatePassthrough", "NewState"=>"9", "NewStateName"=>"FStateError", "Event"=>"16", "EventName"=>"FEventCheckAndCompleteReadsFailed", "ErrorCode"=>"0x8007139f", "EventReceivedTime"=>"2018-12-31 18:09:36", "SourceModuleName"=>"eventlog", "SourceModuleType"=>"im_msvistalog", "message"=>"RDP_SEC: An error was encountered when transitioning from FStatePassthrough in response to FEventCheckAndCompleteReadsFailed (error code 0x8007139F).", "@version"=>"1", "@timestamp"=>"2018-12-31T18:10:17.821Z", "host"=>"10.109.196.138", "port"=>56968, "type"=>"eventlog"}, @metadata={}, @accessors=#<LogStash::Util::Accessors:0xd65f8ab @store={"EventTime"=>"2018-12-31 18:09:34", "Hostname"=>" -RBKP01", "Keywords"=>4611686018427387904, "EventType"=>"WARNING", "SeverityValue"=>3, "Severity"=>"WARNING", "EventID"=>226, "SourceName"=>"Microsoft-Windows-RemoteDesktopServices-RdpCoreTS", "ProviderGuid"=>"{1139C61B-B549-4251-8ED3-27250A1EDEC8}", "Version"=>0, "Task"=>4, "OpcodeValue"=>19, "RecordNumber"=>6933, "ActivityID"=>"{F420C7FE-459B-4921-98C1-D356D0570000}", "ProcessID"=>984, "ThreadID"=>10824, "Channel"=>"Microsoft-Windows-RemoteDesktopServices-RdpCoreTS/Operational", "Domain"=>"NT AUTHORITY", "AccountName"=>"NETWORK SERVICE", "UserID"=>"S-1-5-20", "AccountType"=>"Well Known Group", "Category"=>"RemoteFX module", "Opcode"=>"Runtime", "StateTransition"=>"RDP_SEC", "PreviousState"=>"0", "PreviousStateName"=>"FStatePassthrough", "NewState"=>"9", "NewStateName"=>"FStateError", "Event"=>"16", "EventName"=>"FEventCheckAndCompleteReadsFailed", "ErrorCode"=>"0x8007139f", "EventReceivedTime"=>"2018-12-31 18:09:36", "SourceModuleName"=>"eventlog", "SourceModuleType"=>"im_msvistalog", "message"=>"RDP_SEC: An error was encountered when transitioning from FStatePassthrough in response to FEventCheckAndCompleteReadsFailed (error code 0x8007139F).", "@version"=>"1", "@timestamp"=>"2018-12-31T18:10:17.821Z", "host"=>"10.109.196.138", "port"=>56968, "type"=>"eventlog"}, @lut={"type"=>[{"EventTime"=>"2018-12-31 18:09:34", "Hostname"=>" -RBKP01", "Keywords"=>4611686018427387904, "EventType"=>"WARNING", "SeverityValue"=>3, "Severity"=>"WARNING", "EventID"=>226, "SourceName"=>"Microsoft-Windows-RemoteDesktopServices-RdpCoreTS", "ProviderGuid"=>"{1139C61B-B549-4251-8ED3-27250A1EDEC8}", "Version"=>0, "Task"=>4, "OpcodeValue"=>19, "RecordNumber"=>6933, "ActivityID"=>"{F420C7FE-459B-4921-98C1-D356D0570000}", "ProcessID"=>984, "ThreadID"=>10824, "Channel"=>"Microsoft-Windows-RemoteDesktopServices-RdpCoreTS/Operational", "Domain"=>"NT AUTHORITY", "AccountName"=>"NETWORK SERVICE", "UserID"=>"S-1-5-20", "AccountType"=>"Well Known Group", "Category"=>"RemoteFX module", "Opcode"=>"Runtime", "StateTransition"=>"RDP_SEC", "PreviousState"=>"0", "PreviousStateName"=>"FStatePassthrough", "NewState"=>"9", "NewStateName"=>"FStateError", "Event"=>"16", "EventName"=>"FEventCheckAndCompleteReadsFailed", "ErrorCode"=>"0x8007139f", "EventReceivedTime"=>"2018-12-31 18:09:36", "SourceModuleName"=>"eventlog", "SourceModuleType"=>"im_msvistalog", "message"=>"RDP_SEC: An error was encountered when transitioning from FStatePassthrough in response to FEventCheckAndCompleteReadsFailed (error code 0x8007139F).", "@version"=>"1", "@timestamp"=>"2018-12-31T18:10:17.821Z", "host"=>"10.109.196.138", "port"=>56968, "type"=>"eventlog"}, "type"], "[program]"=>[{"EventTime"=>"2018-12-31 18:09:34", "Hostname"=>" -RBKP01", "Keywords"=>4611686018427387904, "EventType"=>"WARNING", "SeverityValue"=>3, "Severity"=>"WARNING", "EventID"=>226, "SourceName"=>"Microsoft-Windows-RemoteDesktopServices-RdpCoreTS", "ProviderGuid"=>"{1139C61B-B549-4251-8ED3-27250A1EDEC8}", "Version"=>0, "Task"=>4, "OpcodeValue"=>19, "RecordNumber"=>6933, "ActivityID"=>"{F420C7FE-459B-4921-98C1-D356D0570000}", "ProcessID"=>984, "ThreadID"=>10824, "Channel"=>"Microsoft-Windows-RemoteDesktopServices-RdpCoreTS/Operational", "Domain"=>"NT AUTHORITY", "AccountName"=>"NETWORK SERVICE", "UserID"=>"S-1-5-20", "AccountType"=>"Well Known Group", "Category"=>"RemoteFX module", "Opcode"=>"Runtime", "StateTransition"=>"RDP_SEC", "PreviousState"=>"0", "PreviousStateName"=>"FStatePassthrough", "NewState"=>"9", "NewStateName"=>"FStateError", "Event"=>"16", "EventName"=>"FEventCheckAndCompleteReadsFailed", "ErrorCode"=>"0x8007139f", "EventReceivedTime"=>"2018-12-31 18:09:36", "SourceModuleName"=>"eventlog", "SourceModuleType"=>"im_msvistalog", "message"=>"RDP_SEC: An error was encountered when transitioning from FStatePassthrough in response to FEventCheckAndCompleteReadsFailed (error code 0x8007139F).", "@version"=>"1", "@timestamp"=>"2018-12-31T18:10:17.821Z", "host"=>"10.109.196.138", "port"=>56968, "type"=>"eventlog"}, "program"], "[host]"=>[{"EventTime"=>"2018-12-31 18:09:34", "Hostname"=>" -RBKP01", "Keywords"=>4611686018427387904, "EventType"=>"WARNING", "SeverityValue"=>3, "Severity"=>"WARNING", "EventID"=>226, "SourceName"=>"Microsoft-Windows-RemoteDesktopServices-RdpCoreTS", "ProviderGuid"=>"{1139C61B-B549-4251-8ED3-27250A1EDEC8}", "Version"=>0, "Task"=>4, "OpcodeValue"=>19, "RecordNumber"=>6933, "ActivityID"=>"{F420C7FE-459B-4921-98C1-D356D0570000}", "ProcessID"=>984, "ThreadID"=>10824, "Channel"=>"Microsoft-Windows-RemoteDesktopServices-RdpCoreTS/Operational", "Domain"=>"NT AUTHORITY", "AccountName"=>"NETWORK SERVICE", "UserID"=>"S-1-5-20", "AccountType"=>"Well Known Group", "Category"=>"RemoteFX module", "Opcode"=>"Runtime", "StateTransition"=>"RDP_SEC", "PreviousState"=>"0", "PreviousStateName"=>"FStatePassthrough", "NewState"=>"9", "NewStateName"=>"FStateError", "Event"=>"16", "EventName"=>"FEventCheckAndCompleteReadsFailed", "ErrorCode"=>"0x8007139f", "EventReceivedTime"=>"2018-12-31 18:09:36", "SourceModuleName"=>"eventlog", "SourceModuleType"=>"im_msvistalog", "message"=>"RDP_SEC: An error was encountered when transitioning from FStatePassthrough in response to FEventCheckAndCompleteReadsFailed (error code 0x8007139F).", "@version"=>"1", "@timestamp"=>"2018-12-31T18:10:17.821Z", "host"=>"10.109.196.138", "port"=>56968, "type"=>"eventlog"}, "host"]}>>], :response=>{"create"=>{"_index"=>"logstash-2018.12.31", "_type"=>"eventlog", "_id"=>"AWgFdZRpBNPXRS-PpSTB", "status"=>400, "error"=>"MapperParsingException[failed to parse [ErrorCode]]; nested: NumberFormatException[For input string: \"0x8007139f\"]; "}}, :level=>:warn}