I have been facing issues using Winlogbeats to ship localhost logs (application, system, security, etc.) to Elasticsearch.
I have been following the instructions in the documentation, however, I am ONLY able to start the logs shipping to ES with the following command:
PS> .\winlogbeat.exe -c .\winlogbeat.yml -e
This displays DEBUG, INFO etc in the terminal window while operational and the only way for me to stop it is with Ctrl C. This is causing my logs to get corrupted and they cannot be viewed in Windows Event Viewer after Force Stopping Winlgbearts.
The Start-Service winlogbeat command does not initiate logs shipping to ES either.
Request please provide me with link to the correct procedures to Start and Stop the WInlogbeats Service on WInodws 10 using Powershell; or elaborate on the correct procedures here.
Any help is much appreciated!
Thanks in advance!