Graylog2 / Graylog2/collector

Feature Request: Add the possiblity to send Windows Logs via etw provider

Open
#82 0 comments 0 reactions 0 assignees View on GitHub
feature
Dominant language
Go
Stars
1
Forks
0
Avg merge
3d 1h
Merged PRs (30d)
7

Description

Windows DNS-Logging: https://learn.microsoft.com/en-us/windows-server/networking/dns/dns-logging-and-diagnostics; ETW was invented to deal with high volumes of data which DNS usually causes

Filebeat Standalone comes with the capability to consume logs from Windows ETW: https://www.elastic.co/docs/reference/beats/filebeat/filebeat-input-etw, NXLog does it only in the Enterprise Version

Having this capability as part of Graylog Collector it would be possible to use it as a single Log Collector on Windows Systems.

Contributor guide

Open the contributing guide

Research direction

No repository files, tests, or entry points are named. Start with the linked Windows DNS logging and ETW documentation and the Filebeat ETW input reference, then inspect the collector's Windows input boundaries. Done means the collector can consume the requested Windows ETW logs as a supported standalone input.

Written by the indexing model from the issue text.

Assessment

Tech stack
go
Domain
observability-sre, operating-systems
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Quiet
Clarity
Needs clarification
Newbie friendliness
30/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.