Hello from Japan
I have a question for you respected engineers.
I am an inexperienced Japanese engineer with Elastic search.
I have installed winlogbeat on my Windows PC and have built an environment to send Windows logs to elasticsearch for analysis by kibana.
I want to send Removable storage logs to Elasticsearch.
I confirmed that Event ID 4663 in the security item in the Windows event viewer is a removable storage log.
So I created and implemented a yml file like the one below.
winlogbeat.event_logs: - name: Security event_id: 4663
However, Event ID 4663 also outputs logs other than USB.
In addition, it is known that this yml file also sends logs other than Removable storage to Elasticsearch.
How should I write the yml to send logs to Elasticsearch with the event ID 4663 and task category Removable Storage in the Windows Event viewer?
I would like help from all of you respected ELASTIC engineers.
I await your replies and information.