Log Analytics
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Log ingestion windows event viewer

Berry
Observer

hi guys, 

just wondering if we could ingest everything under windows viewer that includes all the subfolder?

i understand we need to specify the path, but there's too many. can we have a wildcard that it will ingest everything?

Appreciate your input 🙂

thank you!

4 REPLIES 4

AntonPineiro
DynaMight Guru
DynaMight Guru

Hi,

You can enable this built-in ingestion rule:

AntonPineiro_0-1787038891530.png

It will be applied in all Windows hosts.

Best regards

❤️ Emacs ❤️ Vim ❤️ Bash ❤️ Perl

hi @AntonPineiro ,

thank you for your swift respond. i understand this will ingest windows system,application and security. do you have any advise if we want to enable it all instead?

Berry_0-1787039522849.png

 

 

Hi,

Since you pay for every data ingested, I do not like ingest everything normally.

I would try to ingest only that mandatory data filtering by log source + pattern lines matching.

Best regards

❤️ Emacs ❤️ Vim ❤️ Bash ❤️ Perl

m3tomlins
Helper

It should be possible to ingest all those windows events, but I would caution that you might also add some matching dt.security_context to the type of records that you might not want EVERYONE in the tenant to have access.

Like the security events, you might limit access via dt.security_context with a matching IAM Policy.

Dynatrace AllStar | Community Champion | @m3tomlins | @performacology | Dynatracer at FreedomPay | Office hours: https://calendly.com/performacology/office-hours

Featured Posts