It seems like they are completely different tools, with filebeat focusing on log files exclusively; I'm also not sure whether Windows Event Log could actually work with that given that it's not just a text file on disk.
m
Mystery Incorporated
10/31/2022, 2:17 AM
Yea filebeat ships windows event logs, as does the newer elastic beat agent
You’re right, for somereason I thought I had done it but now I remember actually I was using filebeat to forward osquery logs until I switched to fleet.
Case still stands that it is madness that we need to use many agents just to do such simple tasks.