The logs-winlog* pipelines are part of the Windows Custom Events integration, it is used for custom logs.
The processing that was done by Winlogbeat is now split between the System and the Windows integration.
For example, the Application, System and Security Event Channels are processed by the System integration, and the Powershell, AppLocker etc are processed by the Windows integration.
The consultant that built the initial configs had everything as Custom Windows Log, so none of the pipelines are being used. I need to switch to the System and Windows integrations.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.