I'm student and i need to collect log on Active directory so i will install winlogbeat on it to send event log on logstash but i've a question because this AD is very sensitive pour the enterprise. My question is when winlogbeat send event log to logstash. he will store the logs in ./ProgramDate/winlogbeat/Logs. Winlogbeat delete those log or he will keep those log ?
In my case i have Winlogbeat => logstash => elastic <= kibana
I hope to be clear.
thx for help