https://github.com/osquery/osquery logo
Title
a

alessandrogario

10/30/2022, 11:14 AM
It seems like they are completely different tools, with filebeat focusing on log files exclusively; I'm also not sure whether Windows Event Log could actually work with that given that it's not just a text file on disk.
m

Mystery Incorporated

10/31/2022, 2:17 AM
Yea filebeat ships windows event logs, as does the newer elastic beat agent
a

alessandrogario

10/31/2022, 2:28 AM
m

Mystery Incorporated

10/31/2022, 2:42 AM
You’re right, for somereason I thought I had done it but now I remember actually I was using filebeat to forward osquery logs until I switched to fleet. Case still stands that it is madness that we need to use many agents just to do such simple tasks.