We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
Would it be possible to have a functionality which would allow to read .evt files directly ? Something like :
winlogbeat: prospectors: - input_type: winlog paths: - C:\System32\Winevt\Logs\ *.evt
Would it be possible to have a functionality which would allow to read .evt files directly ?
Something like :
winlogbeat:
prospectors:
- input_type: winlog
paths:
- C:\System32\Winevt\Logs\ *.evt