Log shipping question

Hi,

I'm new to ELK. My setup is I have a dedicated server for ELK and I have two servers to which I will get the logs which are windows event logs. Here are my questions:

Do I need to install a log shipper for each of my 2 servers(source of logs)? What logs shipper is the best?

What really happens when logs are shipped to ELK? Are the logs copied to the ELK server making it the central repository of logs?

Since in windows logs are archived when it reaches a certain file size, can ELK be able to read archived windows event logs?

Thanks!

FYI we’ve renamed ELK to the Elastic Stack, otherwise beats feels left out :wink:

Yes, and given these are Windows event logs then winlogbeat is the best one.

They are copied/sent to Elasticsearch.

That I don't know sorry! There is Configure Winlogbeat | Winlogbeat Reference [8.11] | Elastic but not sure what happens if they are archived by Windows.

1 Like

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.