Closed Hoverbear closed 3 years ago
I would love to see broader Windows support, especially for Event Logs.
I'd also love to see Windows event logging support. I think there is a huge community that would gladly migrate from beats/logstash to Vector if there were support for this. I currently run lots of collectors for an MSSP that are all built on the aforementioned platforms, but with Elastic's recent licensing change, we are looking to move. There are a lot of great benefits by going with Vector, but lack of Windows event logging support is keeping us from adopting.
BTW, I absolutely love the pipeline unit testing. Such a great feature! 💯
I see adding support for the Windows event log as a can of worms. You have no idea what you are getting into when you start doing that. Let me only refer you to https://github.com/elastic/beats/issues/16334. Winlogbeat is doing/planning to do a lot like GUID lookups and so on that are best done by the agent on the system that emits the logs. I plan to use Vector as collection pipeline for almost anything, including Windows, but not for the event log.
This issue seems to be a duplicate of #1206, I guess one of the two should be closed. Probably the one that was opened after the other, so this (#2719) one.
Agreed, this is a duplicate of #1206, thanks @ypid-geberit.
Source: https://gitter.im/timberio-vector/community?at=5ed5dd5e4c9b0f060d3b616a
This started with a user is reporting issues with the File source on Windows, specifically the Fingerprinter. Unfortunately these files seem to be compressed and non-utf-8. We may need to add a specific source for this. It seems to be a WIndows service we could access via Winapis?
They were trying to do this:
I then recommended:
This did not resolve the problem.
Some more verbose output:
These service files are not plaintext or easily accessible: