Objective: get a saved Windows event log file (xml / json) loaded into ELK.
The file can have different object of arrays, but we can just list all of them, or I'll keep adding more as the data changes.
Input file: Json / XML
- I have a script that parses Windows .evtx to XML and json formats.
Elasticsearch:
- it's a fresh install, non-production, hosted localy in a vm.
I basically need help in forwarding that files into ELK so I'll see some results in Kibana.
which file is easier is best, either the XML or Json.
Examples attached.
Hi
I am a qualified python developer with rich experiences of elasticsearch. I am interested in this project. I am ready to start the work.
Best Regards,
Yongtao
3 year of ELK stack experience.
Worked with naukri dot com and migrated their search functionality from lucene to elasticsearch and executed projects single handedly.
Can start this project immediately.
I did completed the similar setup in the past wherein we were forwarding LoadBalancer data to the Elasticsearch via Logstash. I would request if you can share me dummy json which I can parse it to Elasticsearch and make some dashboard out of it for the Kibana.
If you feel the test setup is worth, then only you award me.