https://github.com/osquery/osquery logo
d

Daemon G.

07/09/2021, 2:26 PM
Hello! Recently came across OSQuery and I'm currently playing around with it and Kibana. I have imported the dashboards provided by the osquery module for FileBeat and I'm seeing some errors in the visualizations such as:
Copy code
Saved field "osquery.result.host_identifier" of index pattern "osquery-*" is invalid for use with the "Unique Count" aggregation.
Anyone else happen across this and know of a solution?
l

Louis Ong

07/28/2021, 2:44 AM
perhaps you should try ask in https://discuss.elastic.co/tag/filebeat