Event viewer logs

Coralogix provides a seamless integration with Winlogbeat to help you can send your Windows event viewer logs directly to Coralogix and parse them according to your needs.

Prerequisites

General

Private Key – A unique ID which represents your company, this Id will be sent to your mail once you register to Coralogix.

Company Id – A unique number which represents your company. You can get your company id from the settings tab in the Coralogix dashboard.

Application Name – The name of your main application, for example, a company named “SuperData” would probably insert the “SuperData” string parameter or if they want to debug their test environment they might insert the “SuperData– Test”.

SubSystem Name – Your application probably has multiple subsystems, for example, Backend servers, Middleware, Frontend servers etc. in order to help you examine the data you need, inserting the subsystem parameter is vital.

Configuration

Open your Winlogbeat configuration file and configure it to use Logstash. For more information about configuring Filebeat to use Logstash please refer to https://www.elastic.co/guide/en/beats/winlogbeat/current/config-winlogbeat-logstash.html

Point your Winlogbeat to output to Coralogix Logstash server:

logstashserver.coralogix.com:5015

In addition, you should add Coralogix configuration from the General section.

Here is a basic example of winlogbeat.yml:

#=========================== Winlogbeat Event Logs ============================

winlogbeat.event_logs:
- name: Application
  fields_under_root: true
  ignore_older: 72h
- name: Security
  fields_under_root: true
- name: System
  fields_under_root: true

fields:
    PRIVATE_KEY: "YOUR_PRIVATE_KEY"
    COMPANY_ID: Your company ID
    APP_NAME: "APP_NAME"
    SUB_SYSTEM: "windows_events"

setup.template.settings:
    index.number_of_shards: 3

#----------------------------- Logstash output --------------------------------

output.logstash:
    enabled: true
    hosts: ["logstashserver.coralogix.com:5015"]
    index: logstash
    tls.certificate_authorities: ["<path to folder with certificates>\\ca.crt"]
    ssl.certificate_authorities: ["<path to folder with certificates>\\ca.crt"]

You should now have your Windows event viewer logs streaming into Coralogix. Not seeing your logs in our LiveTail? Use our in-app chat for support. 

Signup to Coralogix
WordPress Lightbox