{"id":16158,"date":"2020-08-25T11:17:27","date_gmt":"2020-08-25T11:17:27","guid":{"rendered":"https:\/\/dbtut.com\/?p=16158"},"modified":"2020-09-18T08:09:09","modified_gmt":"2020-09-18T08:09:09","slug":"create-kibana-dashboards-for-windows-event-logs","status":"publish","type":"post","link":"https:\/\/dbtut.com\/index.php\/2020\/08\/25\/create-kibana-dashboards-for-windows-event-logs\/","title":{"rendered":"Create Kibana Dashboards For Windows Event Logs"},"content":{"rendered":"<p>In my previous articles, we sent the eventlogs on 10.250.2.224(Windows Server) to logstash running on 10.250.2.222 with winlogbeat, we also configured our logstash and transferred the data to elasticsearch and saw the indexes on kibana. In the same way, I later provided the eventlogs on 10.250.2.225 and 226(Windows Server 2019 servers) to be sent to logstash.<\/p>\n<p>In this article, we will create two separate dashoards on kibana, according to Windows event log counts and Windows log on events.<\/p>\n<p>For this, let&#8217;s first create a new index pattern. For this, let&#8217;s go to Managment&gt; Kibana&gt; Index Pattern&gt; Create index.<\/p>\n<p id=\"mkjJSHr\"><img loading=\"lazy\" decoding=\"async\" width=\"692\" height=\"555\" class=\"size-full wp-image-16159  aligncenter\" src=\"https:\/\/dbtut.com\/wp-content\/uploads\/2020\/08\/img_5f44d0ab084b0.png\" alt=\"\"><\/p>\n<p>Let&#8217;s define our index pattern as winlogbeat- * and proceed with the next step.<\/p>\n<p id=\"LSeNfwY\"><img loading=\"lazy\" decoding=\"async\" width=\"658\" height=\"344\" class=\"size-full wp-image-16160  aligncenter\" src=\"https:\/\/dbtut.com\/wp-content\/uploads\/2020\/08\/img_5f44d0d8f34cc.png\" alt=\"\"><\/p>\n<p>Let&#8217;s select the timestamp and create our index pattern with create index pattern.<\/p>\n<p id=\"SpADuRK\"><img loading=\"lazy\" decoding=\"async\" width=\"673\" height=\"370\" class=\"size-full wp-image-16161  aligncenter\" src=\"https:\/\/dbtut.com\/wp-content\/uploads\/2020\/08\/img_5f44d0fe36ea5.png\" alt=\"\"><\/p>\n<p>Now we can see the event logs of the servers in discover.<\/p>\n<p id=\"aRoVZat\"><img loading=\"lazy\" decoding=\"async\" width=\"682\" height=\"328\" class=\"size-full wp-image-16162  aligncenter\" src=\"https:\/\/dbtut.com\/wp-content\/uploads\/2020\/08\/img_5f44d1298bf08.png\" alt=\"\"><\/p>\n<h3>Creating Kibana Dashboard According to Windows Event Count<\/h3>\n<p>For this, let&#8217;s choose Line chart from Visualize&gt; Create New Visualize.<\/p>\n<p id=\"huJZrRo\"><img loading=\"lazy\" decoding=\"async\" width=\"679\" height=\"451\" class=\"size-full wp-image-16163  aligncenter\" src=\"https:\/\/dbtut.com\/wp-content\/uploads\/2020\/08\/img_5f44d1647c8cc.png\" alt=\"\"><\/p>\n<p>Select the winlogbeat- * index from here.<\/p>\n<p id=\"MxcFhSx\"><img loading=\"lazy\" decoding=\"async\" width=\"687\" height=\"189\" class=\"size-full wp-image-16164  aligncenter\" src=\"https:\/\/dbtut.com\/wp-content\/uploads\/2020\/08\/img_5f44d18e33642.png\" alt=\"\"><\/p>\n<p>Now we just need to select the areas on the X axis and the Y axis of our line chart. Our Y minus will be Count, and we choose the time on the X axis.<\/p>\n<p id=\"ITLtEUm\"><img loading=\"lazy\" decoding=\"async\" class=\" wp-image-16165  aligncenter\" src=\"https:\/\/dbtut.com\/wp-content\/uploads\/2020\/08\/img_5f44d2397e078.png\" alt=\"\" width=\"610\" height=\"675\"><\/p>\n<p>Since I want to show the events that occur per host, I specify that this graph should be edited according to the hostname term from the split chart option.<\/p>\n<p id=\"eVCmDan\"><img loading=\"lazy\" decoding=\"async\" class=\" wp-image-16166  aligncenter\" src=\"https:\/\/dbtut.com\/wp-content\/uploads\/2020\/08\/img_5f44d2d2bc683.png\" alt=\"\" width=\"405\" height=\"594\"><\/p>\n<p>We got a visualize like the one below.<\/p>\n<p id=\"CyEbXWt\"><img loading=\"lazy\" decoding=\"async\" class=\" wp-image-16167  aligncenter\" src=\"https:\/\/dbtut.com\/wp-content\/uploads\/2020\/08\/img_5f44d30bc25fe.png\" alt=\"\" width=\"716\" height=\"374\"><\/p>\n<p>We name and save this visualize to use in the dashboard.<\/p>\n<p id=\"vHfVYEO\"><img loading=\"lazy\" decoding=\"async\" width=\"496\" height=\"317\" class=\"size-full wp-image-16168  aligncenter\" src=\"https:\/\/dbtut.com\/wp-content\/uploads\/2020\/08\/img_5f44d34793c3a.png\" alt=\"\"><\/p>\n<p>Now all we have to do is simple. We come to the Dashboard section and choose Create new dashboard.<\/p>\n<p id=\"qgIzCsh\"><img loading=\"lazy\" decoding=\"async\" class=\" wp-image-16169  aligncenter\" src=\"https:\/\/dbtut.com\/wp-content\/uploads\/2020\/08\/img_5f44d3706003a.png\" alt=\"\" width=\"762\" height=\"280\"><\/p>\n<p>In the Add section, we select Windows Events.<\/p>\n<p id=\"fckLSqC\"><img loading=\"lazy\" decoding=\"async\" class=\" wp-image-16170  aligncenter\" src=\"https:\/\/dbtut.com\/wp-content\/uploads\/2020\/08\/img_5f44d38cc2f7f.png\" alt=\"\" width=\"452\" height=\"206\"><\/p>\n<p>We have now achieved the status we want for the Dashboard, it is enough to save and name this dashdoard we created.<\/p>\n<p id=\"jBJbdIw\"><img loading=\"lazy\" decoding=\"async\" class=\" wp-image-16171  aligncenter\" src=\"https:\/\/dbtut.com\/wp-content\/uploads\/2020\/08\/img_5f44e9d9d8454.png\" alt=\"\" width=\"657\" height=\"377\"><\/p>\n<h3 class=\"LC20lb DKV0Md\">Creating a Dashboard for Log on events in Kibana<\/h3>\n<p>When we come to Kibana discover section, when we make a search like message: &#8220;An account was successfully logged on&#8221;, we will see &#8220;log on&#8221; events on the servers. We save this search to visualize it.<\/p>\n<p id=\"ZKJeDXn\"><img loading=\"lazy\" decoding=\"async\" class=\" wp-image-16172  aligncenter\" src=\"https:\/\/dbtut.com\/wp-content\/uploads\/2020\/08\/img_5f44ea8e6d167.png\" alt=\"\" width=\"716\" height=\"330\"><\/p>\n<p>Let the name of the search we have recorded be Log On Event.<\/p>\n<p id=\"lbpgYJK\"><img loading=\"lazy\" decoding=\"async\" class=\" wp-image-16173  aligncenter\" src=\"https:\/\/dbtut.com\/wp-content\/uploads\/2020\/08\/img_5f44eab7db7e9.png\" alt=\"\" width=\"482\" height=\"346\"><\/p>\n<p>Click on New Visualize from the Visualize section. We can see the search criteria we have recorded from the Vertical Visualize section. We choose Log On Event.<\/p>\n<p id=\"DrNYnvg\"><img loading=\"lazy\" decoding=\"async\" class=\" wp-image-16174  aligncenter\" src=\"https:\/\/dbtut.com\/wp-content\/uploads\/2020\/08\/img_5f44eaf918c19.png\" alt=\"\" width=\"654\" height=\"172\"><\/p>\n<p>There will be count again in the Y-minus. On the X axis, there will be time. There will be a hostname field in the sub bucket. In this way, we run and save visualize.<\/p>\n<p id=\"MXwosiI\"><img loading=\"lazy\" decoding=\"async\" class=\" wp-image-16175  aligncenter\" src=\"https:\/\/dbtut.com\/wp-content\/uploads\/2020\/08\/img_5f44eb3938e05.png\" alt=\"\" width=\"664\" height=\"309\"><\/p>\n<p id=\"fXNfzUm\"><img loading=\"lazy\" decoding=\"async\" width=\"387\" height=\"465\" class=\"size-full wp-image-16176  aligncenter\" src=\"https:\/\/dbtut.com\/wp-content\/uploads\/2020\/08\/img_5f44eb50046ea.png\" alt=\"\"><\/p>\n<p>Save Visualize as Log On Events.<\/p>\n<p id=\"JTiXNBB\"><img loading=\"lazy\" decoding=\"async\" width=\"411\" height=\"270\" class=\"size-full wp-image-16177  aligncenter\" src=\"https:\/\/dbtut.com\/wp-content\/uploads\/2020\/08\/img_5f44eb79896a9.png\" alt=\"\"><\/p>\n<p>By clicking the Dashboard&gt; Create New Dashboard, we select the Log On Events we created and the Windows Events visualizations we created before and save them by naming the dashboard.<\/p>\n<p id=\"NSYwgGD\"><img loading=\"lazy\" decoding=\"async\" class=\" wp-image-16178  aligncenter\" src=\"https:\/\/dbtut.com\/wp-content\/uploads\/2020\/08\/img_5f44ecd39839b.png\" alt=\"\" width=\"668\" height=\"255\"><\/p>\n<p>We have successfully created our dashboards according to windows event counts and log on events. Of course, we created these logs by collecting windows event logs using winlogbeat. We also want to get the CPU, RAM and disk usage graphics of the servers. For this, we will need to install metric beat on our servers. In my next article I will be doing this\u2026.<\/p>\n<p>You can read our other articles in this serie from the links below.<\/p>\n<p><a href=\"https:\/\/dbtut.com\/index.php\/2020\/07\/30\/install-elasticsearch-on-ubuntu-server-19-10\/\" target=\"_blank\" rel=\"noopener noreferrer\">Install Elasticsearch on ubuntu server 19.10<\/a><\/p>\n<p><a href=\"https:\/\/dbtut.com\/index.php\/2020\/08\/04\/install-logstash-on-ubuntu-server-19-10\/\" target=\"_blank\" rel=\"noopener noreferrer\">Install Logstash on Ubuntu Server 19.10<\/a><\/p>\n<p><a href=\"https:\/\/dbtut.com\/index.php\/2020\/08\/09\/install-kibana-on-ubuntu-server-19-10\/\" target=\"_blank\" rel=\"noopener noreferrer\">Install Kibana on Ubuntu Server 19.10<\/a><\/p>\n<p><a href=\"https:\/\/dbtut.com\/index.php\/2020\/08\/15\/install-winlogbeat-on-windows-server-2019\/\" target=\"_blank\" rel=\"noopener noreferrer\">Install Winlogbeat on Windows Server 2019<\/a><\/p>\n<p><a href=\"https:\/\/dbtut.com\/index.php\/2020\/08\/23\/configure-logstash-to-read-log-files-windows\/\" target=\"_blank\" rel=\"noopener noreferrer\">Configure Logstash to Read log files Windows<\/a><\/p>\n<p><a href=\"https:\/\/dbtut.com\/index.php\/2020\/08\/25\/create-kibana-dashboards-for-windows-event-logs\/\" target=\"_blank\" rel=\"noopener noreferrer\">Create Kibana Dashboards For Windows Event Logs<\/a><\/p>\n<div class=\"pvc_clear\"><\/div>\n<p id=\"pvc_stats_16158\" class=\"pvc_stats all  \" data-element-id=\"16158\" style=\"\"><i class=\"pvc-stats-icon medium\" aria-hidden=\"true\"><svg aria-hidden=\"true\" focusable=\"false\" data-prefix=\"far\" data-icon=\"chart-bar\" role=\"img\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" viewBox=\"0 0 512 512\" class=\"svg-inline--fa fa-chart-bar fa-w-16 fa-2x\"><path fill=\"currentColor\" d=\"M396.8 352h22.4c6.4 0 12.8-6.4 12.8-12.8V108.8c0-6.4-6.4-12.8-12.8-12.8h-22.4c-6.4 0-12.8 6.4-12.8 12.8v230.4c0 6.4 6.4 12.8 12.8 12.8zm-192 0h22.4c6.4 0 12.8-6.4 12.8-12.8V140.8c0-6.4-6.4-12.8-12.8-12.8h-22.4c-6.4 0-12.8 6.4-12.8 12.8v198.4c0 6.4 6.4 12.8 12.8 12.8zm96 0h22.4c6.4 0 12.8-6.4 12.8-12.8V204.8c0-6.4-6.4-12.8-12.8-12.8h-22.4c-6.4 0-12.8 6.4-12.8 12.8v134.4c0 6.4 6.4 12.8 12.8 12.8zM496 400H48V80c0-8.84-7.16-16-16-16H16C7.16 64 0 71.16 0 80v336c0 17.67 14.33 32 32 32h464c8.84 0 16-7.16 16-16v-16c0-8.84-7.16-16-16-16zm-387.2-48h22.4c6.4 0 12.8-6.4 12.8-12.8v-70.4c0-6.4-6.4-12.8-12.8-12.8h-22.4c-6.4 0-12.8 6.4-12.8 12.8v70.4c0 6.4 6.4 12.8 12.8 12.8z\" class=\"\"><\/path><\/svg><\/i> <img loading=\"lazy\" decoding=\"async\" width=\"16\" height=\"16\" alt=\"Loading\" src=\"https:\/\/dbtut.com\/wp-content\/plugins\/page-views-count\/ajax-loader-2x.gif\" border=0 \/><\/p>\n<div class=\"pvc_clear\"><\/div>\n","protected":false},"excerpt":{"rendered":"<p>In my previous articles, we sent the eventlogs on 10.250.2.224(Windows Server) to logstash running on 10.250.2.222 with winlogbeat, we also configured our logstash and transferred the data to elasticsearch and saw the indexes on kibana. In the same way, I later provided the eventlogs on 10.250.2.225 and 226(Windows Server 2019 servers) to be sent to &hellip;<\/p>\n<div class=\"pvc_clear\"><\/div>\n<p id=\"pvc_stats_16158\" class=\"pvc_stats all  \" data-element-id=\"16158\" style=\"\"><i class=\"pvc-stats-icon medium\" aria-hidden=\"true\"><svg aria-hidden=\"true\" focusable=\"false\" data-prefix=\"far\" data-icon=\"chart-bar\" role=\"img\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" viewBox=\"0 0 512 512\" class=\"svg-inline--fa fa-chart-bar fa-w-16 fa-2x\"><path fill=\"currentColor\" d=\"M396.8 352h22.4c6.4 0 12.8-6.4 12.8-12.8V108.8c0-6.4-6.4-12.8-12.8-12.8h-22.4c-6.4 0-12.8 6.4-12.8 12.8v230.4c0 6.4 6.4 12.8 12.8 12.8zm-192 0h22.4c6.4 0 12.8-6.4 12.8-12.8V140.8c0-6.4-6.4-12.8-12.8-12.8h-22.4c-6.4 0-12.8 6.4-12.8 12.8v198.4c0 6.4 6.4 12.8 12.8 12.8zm96 0h22.4c6.4 0 12.8-6.4 12.8-12.8V204.8c0-6.4-6.4-12.8-12.8-12.8h-22.4c-6.4 0-12.8 6.4-12.8 12.8v134.4c0 6.4 6.4 12.8 12.8 12.8zM496 400H48V80c0-8.84-7.16-16-16-16H16C7.16 64 0 71.16 0 80v336c0 17.67 14.33 32 32 32h464c8.84 0 16-7.16 16-16v-16c0-8.84-7.16-16-16-16zm-387.2-48h22.4c6.4 0 12.8-6.4 12.8-12.8v-70.4c0-6.4-6.4-12.8-12.8-12.8h-22.4c-6.4 0-12.8 6.4-12.8 12.8v70.4c0 6.4 6.4 12.8 12.8 12.8z\" class=\"\"><\/path><\/svg><\/i> <img loading=\"lazy\" decoding=\"async\" width=\"16\" height=\"16\" alt=\"Loading\" src=\"https:\/\/dbtut.com\/wp-content\/plugins\/page-views-count\/ajax-loader-2x.gif\" border=0 \/><\/p>\n<div class=\"pvc_clear\"><\/div>\n","protected":false},"author":487,"featured_media":16180,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"om_disable_all_campaigns":false,"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"_uf_show_specific_survey":0,"_uf_disable_surveys":false,"footnotes":""},"categories":[3652],"tags":[9880,9879,4651,9878,9877,9876],"class_list":["post-16158","post","type-post","status-publish","format-standard","has-post-thumbnail","","category-elk","tag-central-log-management-with-elastic","tag-create-index-pattern","tag-create-kibana-dashboard","tag-create-kibana-dashboards","tag-create-kibana-dashboards-for-windows-event-logs","tag-creating-a-dashboard-for-security-events-in-kibana"],"aioseo_notices":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v24.9 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Create Kibana Dashboards For Windows Event Logs - Database Tutorials<\/title>\n<meta name=\"description\" content=\"Introduction to Central Log Management with Elastic Stack -7 (Create Kibana Dashboards For Windows Event Logs)\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/dbtut.com\/index.php\/2020\/08\/25\/create-kibana-dashboards-for-windows-event-logs\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Create Kibana Dashboards For Windows Event Logs - Database Tutorials\" \/>\n<meta property=\"og:description\" content=\"Introduction to Central Log Management with Elastic Stack -7 (Create Kibana Dashboards For Windows Event Logs)\" \/>\n<meta property=\"og:url\" content=\"https:\/\/dbtut.com\/index.php\/2020\/08\/25\/create-kibana-dashboards-for-windows-event-logs\/\" \/>\n<meta property=\"og:site_name\" content=\"Database Tutorials\" \/>\n<meta property=\"article:published_time\" content=\"2020-08-25T11:17:27+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2020-09-18T08:09:09+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/dbtut.com\/wp-content\/uploads\/2020\/08\/Ads\u0131z-3.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"882\" \/>\n\t<meta property=\"og:image:height\" content=\"461\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Ahmet Numan AYTEM\u0130Z\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Ahmet Numan AYTEM\u0130Z\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/dbtut.com\/index.php\/2020\/08\/25\/create-kibana-dashboards-for-windows-event-logs\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/dbtut.com\/index.php\/2020\/08\/25\/create-kibana-dashboards-for-windows-event-logs\/\"},\"author\":{\"name\":\"Ahmet Numan AYTEM\u0130Z\",\"@id\":\"https:\/\/dbtut.com\/#\/schema\/person\/ffca49efc4c30bd2bbf99cad3e3f62a6\"},\"headline\":\"Create Kibana Dashboards For Windows Event Logs\",\"datePublished\":\"2020-08-25T11:17:27+00:00\",\"dateModified\":\"2020-09-18T08:09:09+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/dbtut.com\/index.php\/2020\/08\/25\/create-kibana-dashboards-for-windows-event-logs\/\"},\"wordCount\":568,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\/\/dbtut.com\/#organization\"},\"image\":{\"@id\":\"https:\/\/dbtut.com\/index.php\/2020\/08\/25\/create-kibana-dashboards-for-windows-event-logs\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/dbtut.com\/wp-content\/uploads\/2020\/08\/Ads\u0131z-3.jpg\",\"keywords\":[\"Central Log Management with Elastic\",\"create index pattern\",\"create kibana dashboard\",\"Create Kibana Dashboards\",\"Create Kibana Dashboards For Windows Event Logs\",\"Creating a Dashboard for security events in Kibana\"],\"articleSection\":[\"ELK\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\/\/dbtut.com\/index.php\/2020\/08\/25\/create-kibana-dashboards-for-windows-event-logs\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/dbtut.com\/index.php\/2020\/08\/25\/create-kibana-dashboards-for-windows-event-logs\/\",\"url\":\"https:\/\/dbtut.com\/index.php\/2020\/08\/25\/create-kibana-dashboards-for-windows-event-logs\/\",\"name\":\"Create Kibana Dashboards For Windows Event Logs - Database Tutorials\",\"isPartOf\":{\"@id\":\"https:\/\/dbtut.com\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/dbtut.com\/index.php\/2020\/08\/25\/create-kibana-dashboards-for-windows-event-logs\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/dbtut.com\/index.php\/2020\/08\/25\/create-kibana-dashboards-for-windows-event-logs\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/dbtut.com\/wp-content\/uploads\/2020\/08\/Ads\u0131z-3.jpg\",\"datePublished\":\"2020-08-25T11:17:27+00:00\",\"dateModified\":\"2020-09-18T08:09:09+00:00\",\"description\":\"Introduction to Central Log Management with Elastic Stack -7 (Create Kibana Dashboards For Windows Event Logs)\",\"breadcrumb\":{\"@id\":\"https:\/\/dbtut.com\/index.php\/2020\/08\/25\/create-kibana-dashboards-for-windows-event-logs\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/dbtut.com\/index.php\/2020\/08\/25\/create-kibana-dashboards-for-windows-event-logs\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/dbtut.com\/index.php\/2020\/08\/25\/create-kibana-dashboards-for-windows-event-logs\/#primaryimage\",\"url\":\"https:\/\/dbtut.com\/wp-content\/uploads\/2020\/08\/Ads\u0131z-3.jpg\",\"contentUrl\":\"https:\/\/dbtut.com\/wp-content\/uploads\/2020\/08\/Ads\u0131z-3.jpg\",\"width\":882,\"height\":461},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/dbtut.com\/index.php\/2020\/08\/25\/create-kibana-dashboards-for-windows-event-logs\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/dbtut.com\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Create Kibana Dashboards For Windows Event Logs\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/dbtut.com\/#website\",\"url\":\"https:\/\/dbtut.com\/\",\"name\":\"Database Tutorials\",\"description\":\"MSSQL, Oracle, PostgreSQL, MySQL, MariaDB, DB2, Sybase, Teradata, Big Data, NOSQL, MongoDB, Couchbase, Cassandra, Windows, Linux\",\"publisher\":{\"@id\":\"https:\/\/dbtut.com\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/dbtut.com\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/dbtut.com\/#organization\",\"name\":\"dbtut\",\"url\":\"https:\/\/dbtut.com\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/dbtut.com\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/dbtut.com\/wp-content\/uploads\/2021\/02\/dbtutlogo.jpg\",\"contentUrl\":\"https:\/\/dbtut.com\/wp-content\/uploads\/2021\/02\/dbtutlogo.jpg\",\"width\":223,\"height\":36,\"caption\":\"dbtut\"},\"image\":{\"@id\":\"https:\/\/dbtut.com\/#\/schema\/logo\/image\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\/\/dbtut.com\/#\/schema\/person\/ffca49efc4c30bd2bbf99cad3e3f62a6\",\"name\":\"Ahmet Numan AYTEM\u0130Z\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/dbtut.com\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/c0188b8909d8acc22c932103aa4a0bfff080cea47ff20026e44b2fde4bc42194?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/c0188b8909d8acc22c932103aa4a0bfff080cea47ff20026e44b2fde4bc42194?s=96&d=mm&r=g\",\"caption\":\"Ahmet Numan AYTEM\u0130Z\"},\"url\":\"https:\/\/dbtut.com\/index.php\/author\/numanaytemiz\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Create Kibana Dashboards For Windows Event Logs - Database Tutorials","description":"Introduction to Central Log Management with Elastic Stack -7 (Create Kibana Dashboards For Windows Event Logs)","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/dbtut.com\/index.php\/2020\/08\/25\/create-kibana-dashboards-for-windows-event-logs\/","og_locale":"en_US","og_type":"article","og_title":"Create Kibana Dashboards For Windows Event Logs - Database Tutorials","og_description":"Introduction to Central Log Management with Elastic Stack -7 (Create Kibana Dashboards For Windows Event Logs)","og_url":"https:\/\/dbtut.com\/index.php\/2020\/08\/25\/create-kibana-dashboards-for-windows-event-logs\/","og_site_name":"Database Tutorials","article_published_time":"2020-08-25T11:17:27+00:00","article_modified_time":"2020-09-18T08:09:09+00:00","og_image":[{"width":882,"height":461,"url":"https:\/\/dbtut.com\/wp-content\/uploads\/2020\/08\/Ads\u0131z-3.jpg","type":"image\/jpeg"}],"author":"Ahmet Numan AYTEM\u0130Z","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Ahmet Numan AYTEM\u0130Z","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/dbtut.com\/index.php\/2020\/08\/25\/create-kibana-dashboards-for-windows-event-logs\/#article","isPartOf":{"@id":"https:\/\/dbtut.com\/index.php\/2020\/08\/25\/create-kibana-dashboards-for-windows-event-logs\/"},"author":{"name":"Ahmet Numan AYTEM\u0130Z","@id":"https:\/\/dbtut.com\/#\/schema\/person\/ffca49efc4c30bd2bbf99cad3e3f62a6"},"headline":"Create Kibana Dashboards For Windows Event Logs","datePublished":"2020-08-25T11:17:27+00:00","dateModified":"2020-09-18T08:09:09+00:00","mainEntityOfPage":{"@id":"https:\/\/dbtut.com\/index.php\/2020\/08\/25\/create-kibana-dashboards-for-windows-event-logs\/"},"wordCount":568,"commentCount":0,"publisher":{"@id":"https:\/\/dbtut.com\/#organization"},"image":{"@id":"https:\/\/dbtut.com\/index.php\/2020\/08\/25\/create-kibana-dashboards-for-windows-event-logs\/#primaryimage"},"thumbnailUrl":"https:\/\/dbtut.com\/wp-content\/uploads\/2020\/08\/Ads\u0131z-3.jpg","keywords":["Central Log Management with Elastic","create index pattern","create kibana dashboard","Create Kibana Dashboards","Create Kibana Dashboards For Windows Event Logs","Creating a Dashboard for security events in Kibana"],"articleSection":["ELK"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/dbtut.com\/index.php\/2020\/08\/25\/create-kibana-dashboards-for-windows-event-logs\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/dbtut.com\/index.php\/2020\/08\/25\/create-kibana-dashboards-for-windows-event-logs\/","url":"https:\/\/dbtut.com\/index.php\/2020\/08\/25\/create-kibana-dashboards-for-windows-event-logs\/","name":"Create Kibana Dashboards For Windows Event Logs - Database Tutorials","isPartOf":{"@id":"https:\/\/dbtut.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/dbtut.com\/index.php\/2020\/08\/25\/create-kibana-dashboards-for-windows-event-logs\/#primaryimage"},"image":{"@id":"https:\/\/dbtut.com\/index.php\/2020\/08\/25\/create-kibana-dashboards-for-windows-event-logs\/#primaryimage"},"thumbnailUrl":"https:\/\/dbtut.com\/wp-content\/uploads\/2020\/08\/Ads\u0131z-3.jpg","datePublished":"2020-08-25T11:17:27+00:00","dateModified":"2020-09-18T08:09:09+00:00","description":"Introduction to Central Log Management with Elastic Stack -7 (Create Kibana Dashboards For Windows Event Logs)","breadcrumb":{"@id":"https:\/\/dbtut.com\/index.php\/2020\/08\/25\/create-kibana-dashboards-for-windows-event-logs\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/dbtut.com\/index.php\/2020\/08\/25\/create-kibana-dashboards-for-windows-event-logs\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/dbtut.com\/index.php\/2020\/08\/25\/create-kibana-dashboards-for-windows-event-logs\/#primaryimage","url":"https:\/\/dbtut.com\/wp-content\/uploads\/2020\/08\/Ads\u0131z-3.jpg","contentUrl":"https:\/\/dbtut.com\/wp-content\/uploads\/2020\/08\/Ads\u0131z-3.jpg","width":882,"height":461},{"@type":"BreadcrumbList","@id":"https:\/\/dbtut.com\/index.php\/2020\/08\/25\/create-kibana-dashboards-for-windows-event-logs\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/dbtut.com\/"},{"@type":"ListItem","position":2,"name":"Create Kibana Dashboards For Windows Event Logs"}]},{"@type":"WebSite","@id":"https:\/\/dbtut.com\/#website","url":"https:\/\/dbtut.com\/","name":"Database Tutorials","description":"MSSQL, Oracle, PostgreSQL, MySQL, MariaDB, DB2, Sybase, Teradata, Big Data, NOSQL, MongoDB, Couchbase, Cassandra, Windows, Linux","publisher":{"@id":"https:\/\/dbtut.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/dbtut.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/dbtut.com\/#organization","name":"dbtut","url":"https:\/\/dbtut.com\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/dbtut.com\/#\/schema\/logo\/image\/","url":"https:\/\/dbtut.com\/wp-content\/uploads\/2021\/02\/dbtutlogo.jpg","contentUrl":"https:\/\/dbtut.com\/wp-content\/uploads\/2021\/02\/dbtutlogo.jpg","width":223,"height":36,"caption":"dbtut"},"image":{"@id":"https:\/\/dbtut.com\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/dbtut.com\/#\/schema\/person\/ffca49efc4c30bd2bbf99cad3e3f62a6","name":"Ahmet Numan AYTEM\u0130Z","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/dbtut.com\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/c0188b8909d8acc22c932103aa4a0bfff080cea47ff20026e44b2fde4bc42194?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/c0188b8909d8acc22c932103aa4a0bfff080cea47ff20026e44b2fde4bc42194?s=96&d=mm&r=g","caption":"Ahmet Numan AYTEM\u0130Z"},"url":"https:\/\/dbtut.com\/index.php\/author\/numanaytemiz\/"}]}},"amp_enabled":true,"_links":{"self":[{"href":"https:\/\/dbtut.com\/index.php\/wp-json\/wp\/v2\/posts\/16158","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/dbtut.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/dbtut.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/dbtut.com\/index.php\/wp-json\/wp\/v2\/users\/487"}],"replies":[{"embeddable":true,"href":"https:\/\/dbtut.com\/index.php\/wp-json\/wp\/v2\/comments?post=16158"}],"version-history":[{"count":0,"href":"https:\/\/dbtut.com\/index.php\/wp-json\/wp\/v2\/posts\/16158\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/dbtut.com\/index.php\/wp-json\/wp\/v2\/media\/16180"}],"wp:attachment":[{"href":"https:\/\/dbtut.com\/index.php\/wp-json\/wp\/v2\/media?parent=16158"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/dbtut.com\/index.php\/wp-json\/wp\/v2\/categories?post=16158"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/dbtut.com\/index.php\/wp-json\/wp\/v2\/tags?post=16158"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}