Hello,
1st Question:
I am forwarding logs from my collector environment to Kibana using winlogbeat
I am interested in finding who done what.
When I check a log I look for the user that done that, and I can't find - maybe I have bad filtering?
I found this: Logon ID: 0xA42006C
which seems to be hexadecimal, but I can't decipher into proper text.
I guess i'd be looking on User Name, but can't find anything
2nd Question:
How can I forward logs from winevt/logs ? I was thinking of entering the logs path into yml or putting the saved logs so whenever someone opens the saved logs from that folder it will automatically load it into winlogbeat
Any clues?
Thanks
You can also install filebeat in Windows, indeed it is recommended to install beats directly in each one of the nodes you want to monitor or collect logs from.
That clears it up thank you. im also guessing by installing it on windows it doesnt get int he way of the Linux one. also i am only interested in the windows logs so i guess i can delete the Linux filebeat and it wont affect my winlogbeat right?
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.