Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Question: Can I use evtxmon to read from evtx file paths that are active? #19

Open
zhammer opened this issue Feb 12, 2020 · 1 comment

Comments

@zhammer
Copy link

zhammer commented Feb 12, 2020

i'm trying to set up some windows containers so that their windows event log directories are mounted to a shared volume with a sidecar task that monitors and ships directly from those log files.

is this possible with evtxmon? going to try this out on my own but thought i'd post the question here for added support.

(some background trying to get this up with another tool: https://discuss.elastic.co/t/winlogbeat-as-a-docker-sibling-sidecar-container/217409)

@qjerome
Copy link
Contributor

qjerome commented Mar 4, 2020

Hi @zhammer ,

Sorry for the delay ! Maybe you already had the opportunity to test this by now, but normally yes you can do it.

Cheers,

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants