Using NxLog to send Windows Event Logs to Logstash
configure logstash
|
install nxlog-ce
modify nxlog.conf
|
verify configuration file syntax and start service
"C:\Program Files (x86)\nxlog\nxlog.exe" -v && net start nxlog
make some noise on your windows node
then you will see it in elasticsearch
docs
nxlog-reference-manual
using-nxlog-with-elasticsearch-and-kibana
audit-logging-on-windows-with-sysmon-and-nxlog
logstash-event-dependent-configuration
sending-windows-event-logs-to-logsene-using-nxlog-and-logstash