-
Notifications
You must be signed in to change notification settings - Fork 4.9k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
winlogbeat can't read evtx file continuing #33048
Comments
Pinging @elastic/security-external-integrations (Team:Security-External Integrations) |
The .extx reading feature is meant for use with archived logs. If you want to read from the active Security channel then configure Winlogbeat to read from the channel rather than a file.
|
the evtx file was shared in my computer like \\it-data\log\xxx_last.evtx |
I try to fix this question for my code. It's too hard to work. |
Hi! We're labeling this issue as |
Pinging @elastic/sec-windows-platform (Team:Security-Windows Platform) |
In my case,I used the winlogbeat to read evtx file ;
In the beginning it's good for task ,the evtx file be read quickly.
But Suddenly I find a question - If the evtx file be write all the time(for example C:\Windows\System32\winevt\Logs\Security.evtx),the winlogbeat just read to winlogbeat's start time ,so I need restart the winlogbeat for read all data.
How to solve this question?
The text was updated successfully, but these errors were encountered: