This repository has been archived by the owner on Nov 1, 2023. It is now read-only.
[Feature] Use winlogbeat processors to reduce unnecessary information in event logs #42
Labels
enhancement
New feature or request
With current defaults, winlogbeat logs a great deal of superfluous information, such as the PID and TID of the winlogbeat process.
This creates log entries that are full of useless information, which consumes storage space, slows down searching/indexing, and generally makes analyzing the data less pleasant.
Recommend using winlogbeat processors to cut down on some unnecessary fields. I've added the following data to the top of my winlogbeat.yml with good results:
Granted, my approach is a little ham-fisted, and some of the data I've excluded others might want to include. NB that winlog.user.name, etc refers to the user the winlogbeat process is running as, NOT to the user that generated the event, and so is always NT AUTHORITY/SYSTEM.
The text was updated successfully, but these errors were encountered: