CUrrently I don't think Winlogbeat supports continuously reading from an evtx file. Its expected to be a static export and read once. Filebeat 7.16 has a new processor to decode windows event log xml, Decode XML Wineventlog | Filebeat Reference [7.16] | Elastic. So potentially you could convert ur evtx files to xml and then Filbeat could monitor those files?
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.