Hi all, I am trying to setup my elastic server running logstash, kibana and elasticsearch (installed via a binami package)
Everything is running ok but when trying to gather windows logs from a machine using winlogbeat it seems a log is only coming through once every 24 hours, so when i goto create the index it only shows one log per day, which is also reflected in the discovery tab, with the @timestamp selected on the index i only ever see one log on the screen.
the winlogbeat setup is very basic
- name: Application
- name: Security
- name: System
the only other part setup was the logstash output which is as follows
am i missing something fundamental ? i am very new to all this - all running on Windows server by the way.
Should i be sending to logstash or elastic search in the yml file for winlogbeat?
Thanks in advance