Join GitHub today
GitHub is home to over 36 million developers working together to host and review code, manage projects, and build software together.Sign up
Winlogbeat structured event data #1053
I've previously used nxlog but would like to replace it with Winlogbeat... but there is one feature missing for me - parsing of EventData into JSON fields, rather than just having the human readable message. This allows much more powerful analysis in Kibana as you can aggregate on all kinds of things.
<EventData> <Data name="key">value</Data> </EventData>
For some reason a small number of events, such as 1033 from MsiInstaller (logs installation of applications) has the data tags without any attributes - maybe a simple array would be the best way to handle that case?
referenced this issue
Mar 15, 2016
Please leave any questions or feedback (bad or good) here. Thanks!
@andrewkroh This is a quite late follow-up message, but our winlogbeat runs on a machine with Japanese locale. Although message field is rendered fine, message field seems failed to be structured.
Below is the message received in logstash when I logged on(event id 4624) to the Windows server in which winlogbeat v5.1.1 runs. I know v5.1.1 is not the latest winlogbeat, but according to release notes, it should have been capable of structuring event data, right?