Trace Event Logs

Have you see this:

Winlogbeat can read the logs listed by Get-WinEvent -ListLog *.

Only Analytic and Debug logs are based on ETW and Winlogbeat cannot read those. Analytic and Debug logs are disabled and hidden by default in event viewer.

There has been a request to add a feature in Beats for ETW.