...
In AMP, go to the Log Search screen.
Click on Discover.
Use the Change Index Pattern dropdown to view all customer accounts under your Partner account.
Click the View drop down, and change the Index Pattern to (Account ID)_partner.
Below the Search bar, click the link for +Add Filter
Field =
tenant.id
Operator = is
Value = (Partner Customer Account ID)
Below the Search bar, click the link for +Add Filter
Filter #1
Field = tags
Operator = is not one of
Values = armor_agent, windows, linux, oslogs
Type *armor_agent* and hit enter
Type *windows* and hit enter
Type *linux* and hit enter
Type *oslogs* and hit enter
Hit Save
Filter #2
Field = data.type
Operator = is not one of
Values = trend
Type *trend* and hit enter
Filter #3
Field = log.file.path
Operator = is not one of
Values = /opt/armor/filebeat
Type */opt/armor/filebeat * and hit enter
Hit Save
Hit the Refresh button
...