Feature Request: Add the possiblity to send Windows Logs via etw provider
- Dominant language
- Go
- Stars
- 1
- Forks
- 0
- Avg merge
- 3d 1h
- Merged PRs (30d)
- 7
Description
Windows DNS-Logging: https://learn.microsoft.com/en-us/windows-server/networking/dns/dns-logging-and-diagnostics; ETW was invented to deal with high volumes of data which DNS usually causes
Filebeat Standalone comes with the capability to consume logs from Windows ETW: https://www.elastic.co/docs/reference/beats/filebeat/filebeat-input-etw, NXLog does it only in the Enterprise Version
Having this capability as part of Graylog Collector it would be possible to use it as a single Log Collector on Windows Systems.
Contributor guide
Research direction
No repository files, tests, or entry points are named. Start with the linked Windows DNS logging and ETW documentation and the Filebeat ETW input reference, then inspect the collector's Windows input boundaries. Done means the collector can consume the requested Windows ETW logs as a supported standalone input.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- go
- Domain
- observability-sre, operating-systems
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Quiet
- Clarity
- Needs clarification
- Newbie friendliness
- 30/100