Hello,
Have anyone managed to collect windows logs other than the usual Application,System,Security,Setup ?
I am being asked if we can collect Microsoft-Windows-FailoverClustering event ID 1641
If anyone has the inputs.conf file for something like that I would appreciate it.
You can collect any of the eventlog channels
You just have to give the proper name in the inputs.conf stanza. You can find it in the properties of the channel (or you can use some fancy PS command to do it) as Full Name
So for example, for "Applications and Services Logs -> Microsoft -> Windows -> Audio -> CaptureMonitor" it will be "Microsoft-Windows-Audio/CaptureMonitor".
So you'd have to name your stanza
[WinEventLog://Microsoft-Windows-Audio/CaptureMonitor]
PickleRick is spot on - Here is an example of capturing print logs.... Keep in mind that some logs are disabled from operational status, such as the Print Monitor and need to be enabled to start generating logs.
[WinEventLog://Microsoft-Windows-PrintService/Operational]
disabled=0
index=wineventlog
current_only = 0
renderXml = false
checkpointInterval = 5
#REGFIX - HKLM\SYSTEM\CurrentControlSet\services\eventlog\Microsoft-Windows-PrintService/Operational] - DWORD Enabled=00000001
#REGFIX - HKLM\SOFTWARE\Microsoft\Windows\CurrentControlSet\WINEVT\Channels\Microsoft-Windows-PrintService/Operational] - DWORD Enabled=00000001
You can collect any of the eventlog channels
You just have to give the proper name in the inputs.conf stanza. You can find it in the properties of the channel (or you can use some fancy PS command to do it) as Full Name
So for example, for "Applications and Services Logs -> Microsoft -> Windows -> Audio -> CaptureMonitor" it will be "Microsoft-Windows-Audio/CaptureMonitor".
So you'd have to name your stanza
[WinEventLog://Microsoft-Windows-Audio/CaptureMonitor]