I am trying to fully understand the concept of sidecars to monitor my windows eventlogs.
The documentation did allow me to fully configure a test-client, but now, I would have to automate the process.
What I was not able to solve:
How can I have rules, that assign configurations to sidecar-clients? Currently, I have to assign the winlogbeats-config manually for every system. Is there something like a ruleset hidden?
I wanted this to be possible too but it is likely up too someone creating an external script and the Graylog API for now. You can add a thumbs up or comment on the feature request in Github: