December 2017
Intermediate to advanced
434 pages
10h 29m
English
Winlogbeat is a beat dedicated to the Windows platform. Winlogbeat is installed as a Windows service on Windows XP or later to read from one or more event log using Windows APIs. It filters the events based on user-configured criteria and then sends the event data to the configured output, such as Elasticsearch or Logstash.
Winlogbeat can capture event data such as application events, hardware events, security events, and system events.
Read now
Unlock full access