Windows Event logs (winlog)
Last updated
Was this helpful?
Supported event types: logs
The Windows Event logs (winlog) input plugin lets you read Windows Event logs.
The plugin supports the following configuration parameters:
channels
A comma-separated list of channels to read from.
none
db
Set the path to save the read offsets. (optional)
none
interval_sec
Set the polling interval for each channel. (optional)
1
interval_nsec
Set the polling interval for each channel in nanoseconds. (optional)
0
string_inserts
Whether to include string inserts in output records.
true
use_ansi
Use ANSI encoding for Event Log messages. This can help on older Windows versions that return blank strings with wide-character decoding.
false
If db isn't set, the plugin will read channels from the beginning on each startup.
Here is a minimum configuration example.
pipeline:
inputs:
- name: winlog
channels: setup,Windows Powershell
interval_sec: 1
db: winlog.sqlite
outputs:
- name: stdout
match: '*'Some Windows Event Log channels, like Security, require administrative privileges for reading. In this case, you need to run Fluent Bit as an administrator.
If you want to do a test, you can run this plugin from the command line:
Last updated
Was this helpful?
Was this helpful?
[INPUT]
Name winlog
Channels Setup,Windows PowerShell
Interval_Sec 1
DB winlog.sqlite
[OUTPUT]
Name stdout
Match *fluent-bit -i winlog -p 'channels=Setup' -o stdout