We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
Would it be possible to have a functionality which would allow to read .evt files directly ? Something like :
winlogbeat: prospectors: - input_type: winlog paths: - C:\System32\Winevt\Logs\ *.evt