hi, im using winlogbeat 6.7.1 version for collecting event logs. I have a lot of application witch all starts with the same name on the beginning and it will be very useful to filter application by using application name and *.
For example: winlogbeat.event_logs: - name: Application provider: - docker*
The provider filter is built on the XML filtering that Windows supports. There is no support for wildcards or xpath functions like startswith or contains hence Winlogbeat doesn't support them with the provider setting.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.