A set of install scripts and configurations for Elastic Winglogbeat.
- Download the windowsdeploy repo
- Unzip windowsdeply on target machine.
- Run windowsdeploy/installservices.ps1 as an administrator.
- Confirm services were installed correctly.
- Create winlogbeat* index pattern in Kibana.
If you need to start services on machines within the domain, inside the /scripts/
folder is a PowerShell script to start the WinlogBeats and Sysmon services.