fluent / fluent/fluent-plugin-windows-eventlog
Feature Request: Parse Applications and Service Logs
- Dominant language
- Ruby
- Stars
- 32
- Forks
- 19
- Avg merge
- 2d 23h
- Merged PRs (30d)
- 1
Description
We Run Sysmon on our servers and we would like to parse the Applications and Service Logs\Microsoft\Windows\Sysmon\Operational Log
The Log format is below. Hope you can help. Some info has been obscured for security purposes.
Network connection detected:
UtcTime: 2018-01-15 20:21:12.958
ProcessGuid: {2d8e38d1-5fa9-5a4d-0000-001022780800}
ProcessId: 11556
Image: D:\Program Files (x86)\Websense\Web Security\bin\BrokerService.exe
User: NT AUTHORITY\SYSTEM
Protocol: tcp
Initiated: false
SourceIsIpv6: false
SourceIp: X.X.X.X
SourceHostname: sytemname1.example.com
SourcePort: 55880
SourcePortName:
DestinationIsIpv6: false
DestinationIp: X.X.X.X
DestinationHostname: sytemname2.example.com
DestinationPort: 48792
DestinationPortName:
Contributor guide
No contributing guide indexed for this repository
Assessment
This issue has not been assessed yet.