How can i use the eventdata param1 to filter in winlogbeat?
currently, I am using regex on the message but hoping to avoid it for performance.
message: "The Citrix Universal Printing Service*"
This is the field name that contains the data in param1: event_data.param1
- name: System
- Service Control Manager
event_id: 7036, 7031
event_data.param1: "Citrix Universal Printing Service"
This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.