I have some Windows clients and servers.
They have Sysmon, and log are sent with Winlogbeat to Logstash, then Logstash send it to Graylog with GELF type.
That works, but I have this:
Like you can see, the red arrow shows the field who I have, but how can I have the fields form the blue arrow? (Image, SourceIP, DestinationIP…)