fluent / fluent/fluent-plugin-windows-eventlog

Feature Request: Parse Applications and Service Logs

Open
#11 3 comments 0 reactions 0 assignees View on GitHub
enhancement in_windows_eventlog(old)
Dominant language
Ruby
Stars
32
Forks
19
Avg merge
2d 23h
Merged PRs (30d)
1

Description

We Run Sysmon on our servers and we would like to parse the Applications and Service Logs\Microsoft\Windows\Sysmon\Operational Log

The Log format is below. Hope you can help. Some info has been obscured for security purposes.

Network connection detected:
UtcTime: 2018-01-15 20:21:12.958
ProcessGuid: {2d8e38d1-5fa9-5a4d-0000-001022780800}
ProcessId: 11556
Image: D:\Program Files (x86)\Websense\Web Security\bin\BrokerService.exe
User: NT AUTHORITY\SYSTEM
Protocol: tcp
Initiated: false
SourceIsIpv6: false
SourceIp: X.X.X.X
SourceHostname: sytemname1.example.com
SourcePort: 55880
SourcePortName:
DestinationIsIpv6: false
DestinationIp: X.X.X.X
DestinationHostname: sytemname2.example.com
DestinationPort: 48792
DestinationPortName:

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.