Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Give Winlogbeat the capability to grab logs that are written to log files. #20433

Closed
A-Hall opened this issue Aug 4, 2020 · 2 comments
Closed

Comments

@A-Hall
Copy link
Member

A-Hall commented Aug 4, 2020

Describe the enhancement:

Give Winlogbeat the ability to read and parse log files on Windows systems, similar to Filebeat.

Describe a specific use case for the enhancement or feature:

Some logs are not written to the Windows Event Logs, such as the [Windows Defender firewall logs](Give Winlogbeat the capability to grab some logs that are written to log files.). It would be nice if a single Beat endpoint could handle all of the Windows logs, including the ones that are not written to the Event Logs.

@botelastic botelastic bot added the needs_team Indicates that the issue/PR needs a Team:* label label Aug 4, 2020
@elasticmachine
Copy link
Collaborator

Pinging @elastic/siem (Team:SIEM)

@botelastic botelastic bot removed the needs_team Indicates that the issue/PR needs a Team:* label label Aug 9, 2020
@andrewkroh
Copy link
Member

This is not a feature that's on the Winlogbeat roadmp. But being able to read the Windows event logs is something that Filebeat will be able to accomplish (see #19622) as we consolidate all of the log reading features into it.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

4 participants