@tmacgbay Thanks for your support.
I am taking the necessary care with the YAML formatting. I am doing the edits using Visual Code.
I tried to do as posted above, but I keep getting logs from a specific user. Both sidecar.log and winlogbeat.log showed no errors.
sidecar.log:
time="2022-03-25T11:45:03-03:00" level=info msg="[winlogbeat] Configuration change detected, rewriting configuration file."
time="2022-03-25T11:45:03-03:00" level=info msg="[winlogbeat] Stopping"
time="2022-03-25T11:45:04-03:00" level=info msg="[winlogbeat] Starting (svc driver)"
winlogbeat:
2022-03-25T11:45:05.025-0300 INFO instance/beat.go:686 Home path: [C:\Program Files\Graylog\sidecar] Config path: [C:\Program Files\Graylog\sidecar] Data path: [C:\Program Files\Graylog\sidecar\cache\winlogbeat\data] Logs path: [C:\Program Files\Graylog\sidecar\logs] Hostfs Path: [/]
2022-03-25T11:45:05.028-0300 INFO instance/beat.go:694 Beat ID: 2463d591-5825-4e79-8465-1350a716c9e3
2022-03-25T11:45:05.029-0300 INFO [beat] instance/beat.go:1040 Beat info {"system_info": {"beat": {"path": {"config": "C:\\Program Files\\Graylog\\sidecar", "data": "C:\\Program Files\\Graylog\\sidecar\\cache\\winlogbeat\\data", "home": "C:\\Program Files\\Graylog\\sidecar", "logs": "C:\\Program Files\\Graylog\\sidecar\\logs"}, "type": "winlogbeat", "uuid": "2463d591-5825-4e79-8465-1350a716c9e3"}}}
2022-03-25T11:45:05.029-0300 INFO [beat] instance/beat.go:1049 Build info {"system_info": {"build": {"commit": "1d05ba86138cfc9a5ae5c0acc64a57b8d81678ff", "libbeat": "7.17.1", "time": "2022-02-23T23:58:09.000Z", "version": "7.17.1"}}}
2022-03-25T11:45:05.029-0300 INFO [beat] instance/beat.go:1052 Go runtime info {"system_info": {"go": {"os":"windows","arch":"amd64","max_procs":2,"version":"go1.17.6"}}}
2022-03-25T11:45:05.033-0300 INFO [beat] instance/beat.go:1056 Host info {"system_info": {"host": {"architecture":"x86_64","boot_time":"2022-03-22T13:38:53.87-03:00","name":"DC01","ip":["10.0.0.12/24","::1/128","127.0.0.1/8","fe80::5efe:a00:c/128"],"kernel_version":"6.3.9600.16422 (winblue_gdr.131006-1505)","mac":["00:00:00:00:00:00","00:00:00:00:00:00:00:e0"],"os":{"type":"windows","family":"windows","platform":"windows","name":"Windows Server 2012 R2 Standard","version":"6.3","major":3,"minor":0,"patch":0,"build":"9600.0"},"timezone":"-03","timezone_offset_sec":-10800,"id":"e7ff1b2c-d7d3-4a35-9ae0-a840abc75646"}}}
2022-03-25T11:45:05.033-0300 INFO [beat] instance/beat.go:1085 Process info {"system_info": {"process": {"cwd": "C:\\Windows\\system32", "exe": "C:\\Program Files\\Graylog\\sidecar\\winlogbeat.exe", "name": "winlogbeat.exe", "pid": 5604, "ppid": 504, "start_time": "2022-03-25T11:45:04.906-0300"}}}
2022-03-25T11:45:05.033-0300 INFO instance/beat.go:328 Setup Beat: winlogbeat; Version: 7.17.1
2022-03-25T11:45:05.033-0300 INFO [publisher] pipeline/module.go:113 Beat name: DC01
2022-03-25T11:45:05.033-0300 INFO [winlogbeat] beater/winlogbeat.go:66 State will be read from and persisted to C:\Program Files\Graylog\sidecar\cache\winlogbeat\data\.winlogbeat.yml
2022-03-25T11:45:05.034-0300 INFO instance/beat.go:492 winlogbeat start running.
2022-03-25T11:45:05.034-0300 INFO [monitoring] log/log.go:142 Starting metrics logging every 30s
2022-03-25T11:45:06.056-0300 INFO [publisher_pipeline_output] pipeline/output.go:143 Connecting to backoff(async(tcp://10.0.0.53:5044))
2022-03-25T11:45:06.056-0300 INFO [publisher] pipeline/retry.go:219 retryer: send unwait signal to consumer
2022-03-25T11:45:06.056-0300 INFO [publisher] pipeline/retry.go:223 done
2022-03-25T11:45:06.060-0300 INFO [publisher_pipeline_output] pipeline/output.go:151 Connection to backoff(async(tcp://10.0.0.53:5044)) established
2022-03-25T11:45:35.046-0300 INFO [monitoring] log/log.go:184 Non-zero metrics in the last 30s {"monitoring": {"metrics": {"beat":{"cpu":{"system":{"ticks":171,"time":{"ms":171}},"total":{"ticks":499,"time":{"ms":499},"value":499},"user":{"ticks":328,"time":{"ms":328}}},"handles":{"open":205},"info":{"ephemeral_id":"5e04e733-e9ba-43f0-b94a-c6a78c2d5599","uptime":{"ms":30097},"version":"7.17.1"},"memstats":{"gc_next":11496256,"memory_alloc":6053216,"memory_sys":27429896,"memory_total":53753952,"rss":43646976},"runtime":{"goroutines":52}},"libbeat":{"config":{"module":{"running":0}},"output":{"events":{"acked":312,"active":0,"batches":19,"total":312},"read":{"bytes":114},"type":"logstash","write":{"bytes":95382}},"pipeline":{"clients":11,"events":{"active":8,"published":320,"retry":12,"total":320},"queue":{"acked":312,"max_events":4096}}},"system":{"cpu":{"cores":2}}}}}
2022-03-25T11:46:05.046-0300 INFO [monitoring] log/log.go:184 Non-zero metrics in the last 30s {"monitoring": {"metrics": {"beat":{"cpu":{"system":{"ticks":218,"time":{"ms":47}},"total":{"ticks":905,"time":{"ms":406},"value":905},"user":{"ticks":687,"time":{"ms":359}}},"handles":{"open":209},"info":{"ephemeral_id":"5e04e733-e9ba-43f0-b94a-c6a78c2d5599","uptime":{"ms":60097},"version":"7.17.1"},"memstats":{"gc_next":13199408,"memory_alloc":11951456,"memory_total":91708384,"rss":42913792},"runtime":{"goroutines":52}},"libbeat":{"config":{"module":{"running":0}},"output":{"events":{"acked":250,"active":0,"batches":19,"total":250},"read":{"bytes":114},"write":{"bytes":91633}},"pipeline":{"clients":11,"events":{"active":37,"published":279,"total":279},"queue":{"acked":250}}}}}}
2022-03-25T11:46:35.043-0300 INFO [monitoring] log/log.go:184 Non-zero metrics in the last 30s {"monitoring": {"metrics": {"beat":{"cpu":{"system":{"ticks":359,"time":{"ms":141}},"total":{"ticks":1374,"time":{"ms":469},"value":1374},"user":{"ticks":1015,"time":{"ms":328}}},"handles":{"open":209},"info":{"ephemeral_id":"5e04e733-e9ba-43f0-b94a-c6a78c2d5599","uptime":{"ms":90086},"version":"7.17.1"},"memstats":{"gc_next":12572544,"memory_alloc":6425528,"memory_total":128752264,"rss":43409408},"runtime":{"goroutines":52}},"libbeat":{"config":{"module":{"running":0}},"output":{"events":{"acked":229,"active":0,"batches":22,"total":229},"read":{"bytes":132},"write":{"bytes":91686}},"pipeline":{"clients":11,"events":{"active":8,"published":200,"total":200},"queue":{"acked":229}}}}}}
2022-03-25T11:47:05.043-0300 INFO [monitoring] log/log.go:184 Non-zero metrics in the last 30s {"monitoring": {"metrics": {"beat":{"cpu":{"system":{"ticks":468,"time":{"ms":109}},"total":{"ticks":1780,"time":{"ms":406},"value":1780},"user":{"ticks":1312,"time":{"ms":297}}},"handles":{"open":211},"info":{"ephemeral_id":"5e04e733-e9ba-43f0-b94a-c6a78c2d5599","uptime":{"ms":120086},"version":"7.17.1"},"memstats":{"gc_next":15376672,"memory_alloc":9254384,"memory_total":168663048,"rss":44142592},"runtime":{"goroutines":52}},"libbeat":{"config":{"module":{"running":0}},"output":{"events":{"acked":321,"active":0,"batches":20,"total":321},"read":{"bytes":120},"write":{"bytes":105578}},"pipeline":{"clients":11,"events":{"active":0,"published":313,"total":313},"queue":{"acked":321}}}}}}
2022-03-25T11:47:35.042-0300 INFO [monitoring] log/log.go:184 Non-zero metrics in the last 30s {"monitoring": {"metrics": {"beat":{"cpu":{"system":{"ticks":593,"time":{"ms":125}},"total":{"ticks":2139,"time":{"ms":359},"value":2139},"user":{"ticks":1546,"time":{"ms":234}}},"handles":{"open":211},"info":{"ephemeral_id":"5e04e733-e9ba-43f0-b94a-c6a78c2d5599","uptime":{"ms":150086},"version":"7.17.1"},"memstats":{"gc_next":13201744,"memory_alloc":10772184,"memory_total":206358192,"rss":44777472},"runtime":{"goroutines":52}},"libbeat":{"config":{"module":{"running":0}},"output":{"events":{"acked":248,"active":0,"batches":20,"total":248},"read":{"bytes":120},"write":{"bytes":95614}},"pipeline":{"clients":11,"events":{"active":12,"published":260,"total":260},"queue":{"acked":248}}}}}}
2022-03-25T11:48:05.041-0300 INFO [monitoring] log/log.go:184 Non-zero metrics in the last 30s {"monitoring": {"metrics": {"beat":{"cpu":{"system":{"ticks":671,"time":{"ms":78}},"total":{"ticks":2405,"time":{"ms":266},"value":2405},"user":{"ticks":1734,"time":{"ms":188}}},"handles":{"open":206},"info":{"ephemeral_id":"5e04e733-e9ba-43f0-b94a-c6a78c2d5599","uptime":{"ms":180086},"version":"7.17.1"},"memstats":{"gc_next":11746784,"memory_alloc":7172288,"memory_total":238241208,"rss":42418176},"runtime":{"goroutines":52}},"libbeat":{"config":{"module":{"running":0}},"output":{"events":{"acked":139,"active":0,"batches":20,"total":139},"read":{"bytes":120},"write":{"bytes":67600}},"pipeline":{"clients":11,"events":{"active":0,"published":127,"total":127},"queue":{"acked":139}}}}}}
2022-03-25T11:48:35.044-0300 INFO [monitoring] log/log.go:184 Non-zero metrics in the last 30s {"monitoring": {"metrics": {"beat":{"cpu":{"system":{"ticks":796,"time":{"ms":125}},"total":{"ticks":2874,"time":{"ms":469},"value":2874},"user":{"ticks":2078,"time":{"ms":344}}},"handles":{"open":211},"info":{"ephemeral_id":"5e04e733-e9ba-43f0-b94a-c6a78c2d5599","uptime":{"ms":210086},"version":"7.17.1"},"memstats":{"gc_next":11782976,"memory_alloc":7572224,"memory_total":278319800,"rss":42573824},"runtime":{"goroutines":52}},"libbeat":{"config":{"module":{"running":0}},"output":{"events":{"acked":252,"active":0,"batches":21,"total":252},"read":{"bytes":126},"write":{"bytes":102593}},"pipeline":{"clients":11,"events":{"active":8,"published":260,"total":260},"queue":{"acked":252}}}}}}
2022-03-25T11:49:05.042-0300 INFO [monitoring] log/log.go:184 Non-zero metrics in the last 30s {"monitoring": {"metrics": {"beat":{"cpu":{"system":{"ticks":906,"time":{"ms":110}},"total":{"ticks":3343,"time":{"ms":469},"value":3343},"user":{"ticks":2437,"time":{"ms":359}}},"handles":{"open":211},"info":{"ephemeral_id":"5e04e733-e9ba-43f0-b94a-c6a78c2d5599","uptime":{"ms":240087},"version":"7.17.1"},"memstats":{"gc_next":12459520,"memory_alloc":8499536,"memory_total":320516800,"rss":44085248},"runtime":{"goroutines":52}},"libbeat":{"config":{"module":{"running":0}},"output":{"events":{"acked":374,"active":0,"batches":20,"total":374},"read":{"bytes":120},"write":{"bytes":116320}},"pipeline":{"clients":11,"events":{"active":2,"published":368,"total":368},"queue":{"acked":374}}}}}}