I'm new to WinLogBeat and trying to setup in my work machine and ofcourse due to lack of Admin privileges I'm not able to start WinLogBeat as a service as mentioned in the setup docs. I have couple of questions on how WinLogBeat works, tried exploring in google, but couldn't find an answer.
- Why every tutorial on internet suggests to copy the WinLogBeat dir into C:\program files. Won't it work If this is outside of C drive ?
- Why do we need to start this as a service. I was able to work with FileBeat without having such issues.
- How do WinLogBeat knows that In where to look for Windows services details !
Does it just listens to windows events and keep sending the events to output as per the config mentioned in winlogbeat.yml .