I'd like to ask for help on writing a processor configuration to do the following:
- filter on keyword from the event log message (example the application event log message has the word(s)/phrase - "forcibly closed")
- include the event in the output file
-filter on keyword
- include the event in the output file plus,
- run a powershell script as an extra step it has to do
Can someone give me the actual yml section script for doing this task ?
I could not find more guides for creating filtering/processing scripts for winlogbeat. Please direct me to an online article, ebook or guide to learn more and become an expert in beats/winlogbeats configuration and processing/filtering because we have a huge Windows farm.
Please help. TNX.