Elastic Integration - Looking for a way to ingest custom Windows Event Logs #12374
-
Version2.4.40 Installation MethodSecurity Onion ISO image Descriptionconfiguration Installation TypeStandalone Locationon-prem with Internet access Hardware SpecsExceeds minimum requirements CPU8 RAM32 Storage for /500 Storage for /nsm500 Network Traffic Collectiontap Network Traffic SpeedsLess than 1Gbps StatusYes, all services on all nodes are running OK Salt StatusNo, there are no failures LogsNo, there are no additional clues DetailCurrently SO doesn't have support for the Custom Windows Event Logs integrations. Until this is supported, is there anyway I can ingest a couple of custom Event Viewer logs? Mainly the terminal server related ones. I can see that the Custom Logs integration is supported. But I'm struggling with the config Any help is greatly appreciated Guidelines
|
Beta Was this translation helpful? Give feedback.
Replies: 2 comments
-
I know we can do this with winlogbeat... but it's not listed under our SOC console under Downloads. Only the Elastic Agent is. I understand that the Elastic Agent is better in most cases, but can we still use winlogbeat for edge cases like this? |
Beta Was this translation helpful? Give feedback.
-
Disregard this post! Custom Windows Event Logs integration is present in 2.40.50 |
Beta Was this translation helpful? Give feedback.
Disregard this post!
Custom Windows Event Logs integration is present in 2.40.50