Skip to content

[Winlogbeat] Add option to read .evt and .evtx files #4450

Closed
@ghost

Description

Would it be possible to have a functionality which would allow to read .evt files directly ?
Something like :

winlogbeat:
prospectors:
- input_type: winlog
paths:
- C:\System32\Winevt\Logs\ *.evt

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions