Forum Discussion

ford8k's avatar
ford8k
Copper Contributor
Nov 04, 2019

Ingesting custom logs sources and non-Security event logs

Hi,

 

If we want to ingest a Windows event log that isn't Security, do we need to use some combination of WEF -> PowerShell -> Syslog -> Sentinel?

 

If we want to tail some myapp.log file, can the agent help us or is it a case of writing our own code and - again - crafting syslog messages out of each log entry to send it on to Sentinel?

Resources