August 2025
Intermediate to advanced
344 pages
8h 34m
English
For decades, Windows servers and workstations have written logs to a centralized location: the event log. A mature feature of Windows, the event log exists on every instance of the operating system, but its event logs are circular by design, meaning their initial entries get deleted after the file size reaches a limit. Winlogbeat, the Elastic log collector for Windows, can read these binary logs and then ship them downstream so you won’t lose them before they’re rotated out.
In this chapter, we begin by examining the various types of Windows event logs, including Application, System, Security, and Sysmon. Understanding these ...
Read now
Unlock full access