elastic / beats

:tropical_fish: Beats - Lightweight shippers for Elasticsearch & Logstash
https://www.elastic.co/products/beats
Other
12.13k stars 4.91k forks source link

[Auditbeat] system/package dataset equivalent for Windows #16957

Open n0othing opened 4 years ago

n0othing commented 4 years ago

Describe the enhancement:

Auditbeat can monitor installed packages on Linux and MacOS hosts [1]. It'd be useful to have an equivalent monitoring functionality on Windows machines.

[1] https://www.elastic.co/guide/en/beats/auditbeat/current/auditbeat-dataset-system-package.html

botelastic[bot] commented 3 years ago

This issue has been automatically marked as stale because it has not had recent activity. It will be closed if no further activity occurs. Thank you for your contributions.

elasticmachine commented 3 years ago

Pinging @elastic/security-external-integrations (Team:Security-External Integrations)

botelastic[bot] commented 2 years ago

This issue has been automatically marked as stale because it has not had recent activity. It will be closed if no further activity occurs. Thank you for your contributions.

willemdh commented 2 years ago

Ping

pw64 commented 2 years ago

Ping! This is something that should be working out of the box. Treating Linux and Windows equal ; this makes the SIEM-app worth using. Otherwise you just "ignore", better "drop" 50% of your population.

botelastic[bot] commented 1 year ago

Hi! We just realized that we haven't looked into this issue in a while. We're sorry!

We're labeling this issue as Stale to make it hit our filters and make sure we get back to it as soon as possible. In the meantime, it'd be extremely helpful if you could take a look at it as well and confirm its relevance. A simple comment with a nice emoji will be enough :+1. Thank you for your contribution!

n0othing commented 1 year ago

bump

elasticmachine commented 7 months ago

Pinging @elastic/sec-linux-platform (Team:Security-Linux Platform)