Winlogbeat to logstash, followed the VID tried a number of things, signpost please. #9277
Replies: 1 comment 1 reply
-
Have you tried following the steps at https://docs.securityonion.net/en/2.3/beats.html#winlogbeat? |
Beta Was this translation helpful? Give feedback.
1 reply
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
-
Hello,
I still cannot get Winlogbeat to logstash send logs over to SO. Where am i going wrong? Sorry for re-thread i am sure. Confused, i can see similar thread, but none which i understand.
Things attempted.
The only progress i have made is with the zipped PowerShell install service and actually started, which should be unencrypted, Wireshark sees no plain text on tcp.port == 5044.
The winlogbeat.yml config bellow.
A hopeful reach out here thank you in advance, i am defeated. Moving back from to ELK, SO is a different beast. :S
Kind regards,
Beta Was this translation helpful? Give feedback.
All reactions