Deploying Winlogbeat to collect event logs from a dev environment

(Marcos Felix) #1

Now that I have deployed winlogbeat to collect events from my event viewers, how can I go on about collecting events from my development environment?

Would it work something like this:
Instead of installing winlogbeat locally, I would have to delete that and install winlogbeat on my dev environment? or can I install winlogbeat on my dev environment while keeping it on my host? wouldnt create repeated logs?

could someone shed some light onto this?

(Carlos Pérez Aradros) #2

Hi @Marcos_Felix,

You can send events from many locations. Everything coming from beats include some extra metadata you can use to filter it later on in Elasticsearch, for instance. you can use the beat.hostname field to differenciate production from dev.

(Marcos Felix) #3

I was thinking of installing winlogbeat in each of those environments, would that work or is that a bad way of doing it?

(Carlos Pérez Aradros) #4

That would work

(system) #5

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.