Logging -> Audit shows results of Search -> Database ->Events
search cancel

Logging -> Audit shows results of Search -> Database ->Events

book

Article ID: 190468

calendar_today

Updated On:

Products

Endpoint Detection and Response

Issue/Introduction

Within the Graphic User Interface (GUI) of EDR 3.2-4.3, on the Logging-> Audit page, instead of the audit log entries that are expected, Endpoint Detection and Response (EDR) displays the results for Search -> Database ->Events.
Attempting to search for audit entries (i.e. using "type_id:20 OR type_id:21") returns 0 results even when searching for all time.

Cause

A missing kabana index

Resolution


Upgrade to EDR 4.4 to prevent future occurrences.