You can add a Windows event channel to the Log Insight Windows Agent configuration. The Log Insight Windows Agent will collect the log events and send them to the vRealize Log Insight server.
Field names are restricted. The following names are reserved and cannot be used as field names.
- event_type
- hostname
- source
- text
Prerequisites
Log in to the Windows machine on which you installed the vRealize Log Insight Windows agent and start the Services manager to verify that the vRealize Log Insight agent service is installed.
Procedure
Example: Configurations
See the following [winlog| configuration examples.
[winlog|Events_Firewall ] channel=Microsoft-Windows-Windows Firewall With Advanced Security/Firewall enabled=no
[winlog|custom] channel=Custom tags={"ChannelDescription": "Events testing channel"}