Question about log with winlogbeat and logstash

Hello,

I'm student and i need to collect log on Active directory so i will install winlogbeat on it to send event log on logstash but i've a question because this AD is very sensitive pour the enterprise. My question is when winlogbeat send event log to logstash. he will store the logs in ./ProgramDate/winlogbeat/Logs. Winlogbeat delete those log or he will keep those log ?

In my case i have Winlogbeat => logstash => elastic <= kibana

I hope to be clear.

thx for help

These are the logs that Winlogbeat generates for itself, it's not the data that is it processing.

It will not delete them, no.

ok thx for answer

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.