I’ll look for it. Trying to judege what method is best, OSquery wrote to windoes eventlog and use winlog beat to pick it up with the rest of my eventlogs, osquery read eventlogs and write them to osqueryd.results.log and pick it up with filebeat, or send to kafka direct from osquery.