how can i read an old logfile with winlogbeat. I have seen the following:
winlogbeat.event_logs:
name: ${EVTX_FILE}
no_more_events: stop
But what exactly do I have to write in name/path? Where must my file be located? I have a local evtx-file on my machine and want to send this file to elasticsearch with winlogbeat - logstash.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.