You can add a Windows event channel to the VMware Aria Operations for Logs Windows Agent configuration. The VMware Aria Operations for Logs Windows Agent will collect the log events and send them to the VMware Aria Operations for Logs server.
Field names are restricted. The following names are reserved and cannot be used as field names.
- event_type
- hostname
- source
- text
Prerequisites
Log in to the Windows machine on which you installed the VMware Aria Operations for Logs Windows agent and start the services manager to verify that the VMware Aria Operations for Logs agent service is installed.
Procedure
Example: Configurations
See the following [winlog| configuration examples.
[winlog|Events_Firewall ] channel=Microsoft-Windows-Windows Firewall With Advanced Security/Firewall enabled=no
[winlog|custom] channel=Custom tags={"ChannelDescription": "Events testing channel"}