How can i filter by EventSource, the events are sent from one of our custom applications and i wanted to log only those messages but not all messages for "Application"
for example i want to send the messages only from "Outlook" which is one the "Source" from the below screenshot
What you are showing is correct. Could it be that Winlogbeat has already sent all those records? If you remove the C:\ProgramData\winlogbeat\.winlogbeat.yml file it will resend all those from the last 72h.
Another debugging option is to run Winlogbeat with debug on.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.