Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Winlogbeat - parse and index raw XML representation of Windows events #19576

Closed
eddieturizo opened this issue Jul 2, 2020 · 2 comments
Closed

Comments

@eddieturizo
Copy link

Describe the enhancement:
Parse the raw XML representation of Windows events when using event_logs.include_xml in Winlogbeat.

Describe a specific use case for the enhancement or feature:

Instead of having to use Logstash filter plugins to parse and index the raw XML fields generated after setting event_logs.include_xml, it would be useful if Winglogbeat did this natively.

@botelastic botelastic bot added the needs_team Indicates that the issue/PR needs a Team:* label label Jul 2, 2020
@elasticmachine
Copy link
Collaborator

Pinging @elastic/siem (Team:SIEM)

@botelastic botelastic bot removed the needs_team Indicates that the issue/PR needs a Team:* label label Jul 2, 2020
@jamiehynds
Copy link

Closing this out as we recently implemented the decode_xml processor for Windows events via #23910

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

4 participants