Open steenstra opened 2 weeks ago
Next step: reproduce issue locally.
@steenstra sorry for the late feedback. I check the code and the issue is that the event_tags
option currently does not accept wildcards... Let me see if I can add this...
That's great to know. Do you know what the tag names are that I should use in the meantime?
Is it:
Data_TargetUserName
or TargetUserName
You need to specify the full name IIRC...
Correction. I found the issue. All the Data_*
fields are coming from the XML in the event and where handled differently. I do have a PR (almost) ready and will push in some minutes. I'll link it here for you to test...
@steenstra please test the binary in PR #16008, available as soon as CI finished the tests, and let me know if this fixes the issue!
Relevant telegraf.conf
Logs from Telegraf
System info
Telegraf v1.32.0, Windows Server 2022 21H2
Docker
No response
Steps to reproduce
"*WorkstationName*", "*TargetUserName*"
forevent_tags
Data_TargetUserName
andData_WorkstationName
...Expected behavior
I'd expect there to be tags for
Data_TargetUserName
andData_WorkstationName
Actual behavior
but there’s only fields, no tags. See screenshot.
Additional info
No response