You cannot select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

37 lines
868 B
INI

[query_authlog_root_login]
# The DEFAULT settings can be overridden.
QueryIntervalSecs = 60
QueryTimeoutSecs = 15
QueryIndices = <*-authlog-*>
QueryOnError = preserve
QueryOnMissing = zero
QueryJson = {
"size": 0,
"query": {
"bool": {
"must": [],
"filter": [
{
"range": {
"@timestamp": {
"format": "strict_date_optional_time",
"gte": "now-5m/m",
"lte": "now"
}
}
},
{
"exists": {
"field": "system.auth.user"
}
},
{
"match_phrase": {
"system.auth.user": "root"
}
}
]
}
}
}