18 Aug 2026 05:22 AM
hi guys,
just wondering if we could ingest everything under windows viewer that includes all the subfolder?
i understand we need to specify the path, but there's too many. can we have a wildcard that it will ingest everything?
Appreciate your input 🙂
thank you!
18 Aug 2026 08:41 AM - edited 18 Aug 2026 08:42 AM
Hi,
You can enable this built-in ingestion rule:
It will be applied in all Windows hosts.
Best regards
18 Aug 2026 08:52 AM
hi @AntonPineiro ,
thank you for your swift respond. i understand this will ingest windows system,application and security. do you have any advise if we want to enable it all instead?
18 Aug 2026 02:23 PM
Hi,
Since you pay for every data ingested, I do not like ingest everything normally.
I would try to ingest only that mandatory data filtering by log source + pattern lines matching.
Best regards
18 Aug 2026 10:37 PM
It should be possible to ingest all those windows events, but I would caution that you might also add some matching dt.security_context to the type of records that you might not want EVERYONE in the tenant to have access.
Like the security events, you might limit access via dt.security_context with a matching IAM Policy.
Featured Posts