Functional Testing

  1. Log in to the Windows machine where Elasticsearch is configured.

  2. Open a browser and access http://<localhost>:5601 or http://<host_ip>:5601 to access the Elasticsearch dashboard and enter the configured superuser credentials to log in.

  3. From the dashboard, navigate to Analytics → Discover.

  4. In the search bar, enter keywords related to ESKM events (e.g., ESKM, login, audit, syslog) to filter and view the logs received from the ESKM system.

Screenshot 2025-11-18 121740-20251118-064741.png


Verify ESKM logs

After Filebeat is configured, perform actions on the ESKM server, such as login, logout, or any administrative operation, to ensure new events are captured.