delete all windows events from SO #10104
Replies: 1 comment 3 replies
-
So, just to make sure I understand, you are using Winlogbeat on a WEF Subscription Server to send Forwarded Events into Security Onion, but only about half of the originating servers are represented? Do they all have the same subscription settings? When you say the forwarded logs exist in Event Viewer, do you mean on the original server or on the WEF subscription server? |
Beta Was this translation helpful? Give feedback.
3 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
-
Dear all,
My all 38 servers' windows events are sent to one server and from there I forwarded them to SO with Winlogbeat. I have two issues.
I see that all local server logs are also forwarded (by mistake I forwarded them but then removed them from winlogbeat yml file and restarted the service they are still forwarded.) I like to delete all windows and sysmon events from SO. How can I do that?
I also see that some of the forwarded logs from some servers exist in Windows Event Viewer but they are not forwarded to SO. For example, I have subscriptions from 38 servers but I see only 19 of them on SO. How can I force forward all events from all servers? (Hopefully deleting all Windows events and starting from scratch will solve the issue.)
My config is like the one below.
Thank you very much in advance.
Beta Was this translation helpful? Give feedback.
All reactions