Logstash EVTX Ingestion

Hi Guys,
Is there a way to ingest cold EVTX files with logstash?
The reason I am asking, is that winlogbeat is really slow.
I have big files, some of them takes hours to upload into ELK with winlogbeat.

Thanks

1 Like

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.