Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Windows Event Log integration module for Elastic Agent #20886

Closed
dancs85 opened this issue Sep 1, 2020 · 6 comments
Closed

Windows Event Log integration module for Elastic Agent #20886

dancs85 opened this issue Sep 1, 2020 · 6 comments
Labels
Team:Services (Deprecated) Label for the former Integrations-Services team v7.10.0

Comments

@dancs85
Copy link

dancs85 commented Sep 1, 2020

Describe the enhancement:
The Elastic Agent should have a module that replicates the functionality of Winlogbeat, including the Powershell, Security and Sysmon modules. If possible, Sysmon itself should be able to be bundled in (if licencing allows) as this will populate a lot of the information the SIEM app uses.

Describe a specific use case for the enhancement or feature:
The Windows event logs are used in both Observability and Security arenas.
Bundling sysmon will cover users who don't opt to use the Elastic Endpoint module (I believe Sysmon/Elastic Endpoint generate very similar logs)

@botelastic botelastic bot added the needs_team Indicates that the issue/PR needs a Team:* label label Sep 1, 2020
@elasticmachine
Copy link
Collaborator

Pinging @elastic/ingest-management (Team:Ingest Management)

@botelastic botelastic bot removed the needs_team Indicates that the issue/PR needs a Team:* label label Sep 1, 2020
@ph
Copy link
Contributor

ph commented Sep 2, 2020

@dancs85 Is under our radar, we want to do some refactor of Winlogbeat/filebeat to add to the elastic agent. But having better windows support is one of our priority.

@ph
Copy link
Contributor

ph commented Oct 14, 2020

I think we are able to close this, the Elastic Agent now support the window event logs via #19622

@urso WDYT?

@ph ph added v7.10.0 Team:Services (Deprecated) Label for the former Integrations-Services team labels Oct 14, 2020
@elasticmachine
Copy link
Collaborator

Pinging @elastic/integrations-services (Team:Services)

@ph
Copy link
Contributor

ph commented Oct 14, 2020

Wait, I've misread the ask, the elastic-agent does support the winlog input, we need to have an official integration.

@urso
Copy link

urso commented Oct 14, 2020

The windows package already makes use of the winlog input in Agent. For Sysmon and others we should consider separate integrations. But on the Beats/Agent side itself I think we are done.

@ph ph closed this as completed Oct 29, 2020
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Team:Services (Deprecated) Label for the former Integrations-Services team v7.10.0
Projects
None yet
Development

No branches or pull requests

6 participants