Use Filebeat in MacOS M1 to ship extracted win evtx file to docker ELK

Hi all,

I am new to ELK. I know this may sounds weird. But I am doing some POC and testing by extracting a Sysmon EVTX from a windows server.

The workstation I am using a Mac M1. I installed filebeat in Mac and wanted to ship this offline evtx from M1 to my docker ELK. Is this even possible?

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.