I can catch every log from the computer but I just want the log from one application. I try to make that with the processors on Winlogbeat.
- It's is possible ?
- Did I have to do that with a filter on Logstash ?
Here it's what I catch with the logbeat.
Actualy It's what I have from the cmd line:
Exiting: error initializing processors: failed to initialize condition: missing or invalid condition
And here is my Winlogbeat processors
processors: - include_fields: when: winlog.event_data.ProcessName: 'C:\Program Files (x86)\Microsoft Dynamics NAV\110\RoleTailored Client\Microsoft.Dynamics.Nav.Client.exe' fields: [message, winlog.event_data.ProcessName, winlog.event_data.SubjectUserName]
Kind of regards.
PS: I'm sorry for my english skill