This content Pack is only intended for Windows Security Monitoring.
If you noticed some data about security that is not parsed or missing fields, you can open an issue and I will update the Content Pack.
Tested with Windows 10/11 and Windows Server 2022 and Graylog 5.2.2.
The Content Pack should be compatible with all Graylog 5.X version.
Note this was built without extractors, only pipeline rules.
I will try to test with the latest Graylog version and update the content pack.
I will keep you update, but it is weird that it canât parse this field which I assume is from PowerShell event, but maybe because it contain some simple quote with double brackets ?
First off thanks for all the work youâve put into this. Iâve installed it and most seems to working however I have an issue with the file monitoring dashboard; no events are populating. I notice when i edit the main query itâs only looking for the âwindowsshareâ tag. Where is this tag applied? I only see references to âfilesystemâ in the winlogbeat.yml.
Also are the js scripts included in the winlogbeat zips supposed to run? In the script files themselves they specify theyâre for beats 8.
Sorry for the inconvenience, Iâm currently writing / updating the content pack with winlgobeat/filebeat version 8 and modules with JavaScript are not loaded anymore.
I will try to provide you with the winlogbeat 7 config if needed
I found the yml configs for 7 your posted and made all the required changes. Iâm just confused over the js scripts in the modules folder. I downloaded the beats zips directly from the beats site and even though the version of the exes is 7 the scripts still state they are for beats 8.