I am new to graylog and I have tried setting up sidecar with winlogbeat which seems to be configured properly, but I am not receiving events in graylog. Here are the details -
fields: collector_node_id: graylog-collector-sidecar gl2_source_collector: 429cfebb-462b-45b9-9082-ee958656cb5e output: logstash: hosts: - XX.XX.XX.X:5044 path: data: C:\Program Files\graylog\collector-sidecar\cache\winlogbeat\data logs: C:\Program Files\graylog\collector-sidecar\logs tags: - windows winlogbeat: event_logs: - name: Application - name: System - name: Security
I could see
EventLog[System] successfully published 1 events log entry in winlogbeat log file but in graylog web UI there is no data under search tab.