I’ve dug through the new documentation and (attempted) several collector configurations, but have had no luck.
I have cases where I want both the Windows events, and an A/V flatfile log. Documentation states “The Windows Sidecar package already includes Filebeat and Winlogbeat.” - but it does not cover how to configure both WinLogBeats and FileBeats in the same configuration. What am I missing?
Can someone post a working example so I can see the proper structure?