Install Winlogbeat to shift windows events to PacketAI

Download and Install Winlogbeat

Execute the following script in Powershell to download Winlogbeat
$ProgressPreference = 'SilentlyContinue'
Invoke-WebRequest -Uri -OutFile
Expand-Archive .\
mv .\wlb\winlogbeat-8.4.3-windows-x86_64\ .\winlogbeat\
rm -r .\wlb
rm .\
cd .\winlogbeat

Get PacketAI Winlogbeat Config Template

The default configuration could be generated by using Powershell to run the following command in the winlogbeat folder:
Invoke-WebRequest -Uri "" -OutFile generate-config.ps1
.\generate-config.ps1 -clustername "YOUR_CLUSTER_NAME" -infra "YOUR_PAI_IID" -token "YOUR_PAI_TOKEN"
  • you need to replace YOUR_CLUSTER_NAME with appropriate cluster name. (make sure the cluster name is alpha numeric and lowercase only)
  • you need to replace YOUR_PAI_IID and YOUR_PAI_TOKEN from the Deploy PacketAI/Agent/ Logstash credentials.

Configure Log Source

Configure the log you want to monitor in the generated file: winlogbeat.yml

Start the Service

Start-Service winlogbeat