I noticed that in 6.0 the registry file in c:\ProgramData\winlogbeat.winlogbeat.yml isn't populating the same - am i missing something or is this intentional?
- name: wineventlog
- name: Application
- name: Microsoft-Windows-Diagnostics-Performance/Operational
- name: System
This is definitely a bug. Please open a new issue on Github for this.
The name should be set to
e.Channel rather than
e.API. This must have been introduced when we did a refactoring in 6.0 that allows Winlogbeat to be reading a batch and sending concurrently.
Thanks for the clarification. Also I noticed something that also may be related -
Whenever winlogbeat service is restarted the .winlogbeat.yml is reset and the logs are reset.
That sounds like symptom of the bug rather than a second issue.
This topic was automatically closed after 21 days. New replies are no longer allowed.