Log shipping question

(janus barinan) #1


I'm new to ELK. My setup is I have a dedicated server for ELK and I have two servers to which I will get the logs which are windows event logs. Here are my questions:

Do I need to install a log shipper for each of my 2 servers(source of logs)? What logs shipper is the best?

What really happens when logs are shipped to ELK? Are the logs copied to the ELK server making it the central repository of logs?

Since in windows logs are archived when it reaches a certain file size, can ELK be able to read archived windows event logs?


(Mark Walkom) #2

FYI we’ve renamed ELK to the Elastic Stack, otherwise beats feels left out :wink:

Yes, and given these are Windows event logs then winlogbeat is the best one.

They are copied/sent to Elasticsearch.

That I don't know sorry! There is https://www.elastic.co/guide/en/beats/winlogbeat/current/configuration-winlogbeat-options.html#_event_logs_ignore_older but not sure what happens if they are archived by Windows.

(system) #3

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.