Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- 2025-03-03 00:08:36 -0800 [info]: fluent/log.rb:362:info: init supervisor logger path=nil rotate_age=nil rotate_size=nil
- 2025-03-03 00:08:36 -0800 [info]: fluent/log.rb:362:info: parsing config file is succeeded path="C:\\opt\\fluent\\etc\\fluent\\fluentd.conf"
- 2025-03-03 00:08:36 -0800 [info]: fluent/log.rb:362:info: gem 'fluentd' version '1.18.0'
- 2025-03-03 00:08:36 -0800 [info]: fluent/log.rb:362:info: gem 'fluent-plugin-calyptia-monitoring' version '0.1.3'
- 2025-03-03 00:08:36 -0800 [info]: fluent/log.rb:362:info: gem 'fluent-plugin-elasticsearch' version '5.4.3'
- 2025-03-03 00:08:36 -0800 [info]: fluent/log.rb:362:info: gem 'fluent-plugin-flowcounter-simple' version '0.1.0'
- 2025-03-03 00:08:36 -0800 [info]: fluent/log.rb:362:info: gem 'fluent-plugin-grok-parser' version '2.6.2'
- 2025-03-03 00:08:36 -0800 [info]: fluent/log.rb:362:info: gem 'fluent-plugin-kafka' version '0.19.3'
- 2025-03-03 00:08:36 -0800 [info]: fluent/log.rb:362:info: gem 'fluent-plugin-loki' version '0.3.0'
- 2025-03-03 00:08:36 -0800 [info]: fluent/log.rb:362:info: gem 'fluent-plugin-metrics-cmetrics' version '0.1.2'
- 2025-03-03 00:08:36 -0800 [info]: fluent/log.rb:362:info: gem 'fluent-plugin-opensearch' version '1.1.4'
- 2025-03-03 00:08:36 -0800 [info]: fluent/log.rb:362:info: gem 'fluent-plugin-parser-winevt_xml' version '0.2.7'
- 2025-03-03 00:08:36 -0800 [info]: fluent/log.rb:362:info: gem 'fluent-plugin-prometheus' version '2.1.0'
- 2025-03-03 00:08:36 -0800 [info]: fluent/log.rb:362:info: gem 'fluent-plugin-prometheus_pushgateway' version '0.1.1'
- 2025-03-03 00:08:36 -0800 [info]: fluent/log.rb:362:info: gem 'fluent-plugin-record-modifier' version '2.2.0'
- 2025-03-03 00:08:36 -0800 [info]: fluent/log.rb:362:info: gem 'fluent-plugin-rewrite-tag-filter' version '2.4.0'
- 2025-03-03 00:08:36 -0800 [info]: fluent/log.rb:362:info: gem 'fluent-plugin-s3' version '1.8.1'
- 2025-03-03 00:08:36 -0800 [info]: fluent/log.rb:362:info: gem 'fluent-plugin-sd-dns' version '0.1.0'
- 2025-03-03 00:08:36 -0800 [info]: fluent/log.rb:362:info: gem 'fluent-plugin-td' version '1.2.0'
- 2025-03-03 00:08:36 -0800 [info]: fluent/log.rb:362:info: gem 'fluent-plugin-webhdfs' version '1.6.0'
- 2025-03-03 00:08:36 -0800 [info]: fluent/log.rb:362:info: gem 'fluent-plugin-windows-eventlog' version '0.9.1'
- 2025-03-03 00:08:36 -0800 [info]: fluent/log.rb:362:info: gem 'fluent-plugin-windows-eventlog' version '0.9.0'
- 2025-03-03 00:08:36 -0800 [info]: fluent/log.rb:362:info: gem 'fluent-plugin-windows-exporter' version '1.0.0'
- 2025-03-03 00:08:36 -0800 [info]: fluent/log.rb:362:info: Expanded the pattern %{EVENT_ID:event_id}.*Handle ID:\s*%{NUMBER:handle_id}.*Account Name:\s*%{USERNAME:username}.*ComputerName:\s*%{HOSTNAME:hostname}.*Object Name:\s*%{PATH:object_name}.* into (?<event_id>\d{4}).*Handle ID:\s*(?<handle_id>(?:(?:(?<![0-9.+-])(?>[+-]?(?:(?:[0-9]+(?:\.[0-9]+)?)|(?:\.[0-9]+)))))).*Account Name:\s*(?<username>[a-zA-Z0-9\.\-_]+).*ComputerName:\s*(?<hostname>[a-zA-Z0-9\.\-_]+).*Object Name:\s*(?<object_name>(?:[a-zA-Z]:)?(?:[^\\]+\\)*+).*
- 2025-03-03 00:08:36 -0800 [info]: fluent/log.rb:362:info: adding rewrite_tag_filter rule: event_id [#<Fluent::PluginHelper::RecordAccessor::Accessor:0x00000223b2978588 @keys="event_id">, /^(4660|4663|4656|4659)$/, "", "winevt.filtered", nil]
- 2025-03-03 00:08:38 -0800 [debug]: fluent/log.rb:341:debug: No fluent logger for internal event
- 2025-03-03 00:08:38 -0800 [info]: fluent/log.rb:362:info: using configuration file: <ROOT>
- <source>
- @type windows_eventlog2
- @id windows_eventlog2
- channels security
- read_existing_events true
- tag "winevt.raw"
- <storage>
- @type "local"
- persistent true
- path "C:/logs/buffer/windows_eventlog2.json"
- </storage>
- </source>
- <filter winevt.raw>
- @type parser
- key_name "Description"
- reserve_data true
- <parse>
- @type "grok"
- grok_pattern "%{EVENT_ID:event_id}.*Handle ID:\\s*%{NUMBER:handle_id}.*Account Name:\\s*%{USERNAME:username}.*ComputerName:\\s*%{HOSTNAME:hostname}.*Object Name:\\s*%{PATH:object_name}.*"
- custom_pattern_path "C:/opt/fluent/etc/fluent/custom_patterns.txt"
- </parse>
- </filter>
- <filter winevt.raw>
- @type record_transformer
- enable_ruby true
- <record>
- event_id ${record["event_id"]}
- handle_id ${record["handle_id"]}
- username ${record["username"]}
- hostname ${record["hostname"]}
- object_name ${record["object_name"]}
- timestamp ${Time.at(record["TimeCreated"].to_i).iso8601}
- </record>
- </filter>
- <match winevt.raw>
- @type rewrite_tag_filter
- <rule>
- key "event_id"
- pattern /^(4660|4663|4656|4659)$/
- tag "winevt.filtered"
- </rule>
- </match>
- <match winevt.filtered>
- @type loki
- @id loki_output
- endpoint_url "http://192.168.1.2:3100/loki/api/v1/push"
- remove_keys event_id,handle_id
- <label>
- hostname ${hostname}
- username ${username}
- </label>
- <buffer>
- @type "file"
- path "C:/logs/buffer"
- flush_interval 5s
- </buffer>
- </match>
- <system>
- log_level debug
- </system>
- </ROOT>
- 2025-03-03 00:08:38 -0800 [info]: fluent/log.rb:362:info: starting fluentd-1.18.0 pid=6088 ruby="3.2.6"
- 2025-03-03 00:08:38 -0800 [info]: fluent/log.rb:362:info: spawn command to main: cmdline=["C:/opt/fluent/bin/ruby.exe", "-Eascii-8bit:ascii-8bit", "C:/opt/fluent/bin/fluentd", "-c", "C:\\opt\\fluent\\etc\\fluent\\fluentd.conf", "--under-supervisor"]
- 2025-03-03 00:08:43 -0800 [info]: #0 fluent/log.rb:362:info: init worker0 logger path=nil rotate_age=nil rotate_size=nil
- 2025-03-03 00:08:43 -0800 [info]: fluent/log.rb:362:info: adding filter pattern="winevt.raw" type="parser"
- 2025-03-03 00:08:43 -0800 [info]: #0 fluent/log.rb:362:info: Expanded the pattern %{EVENT_ID:event_id}.*Handle ID:\s*%{NUMBER:handle_id}.*Account Name:\s*%{USERNAME:username}.*ComputerName:\s*%{HOSTNAME:hostname}.*Object Name:\s*%{PATH:object_name}.* into (?<event_id>\d{4}).*Handle ID:\s*(?<handle_id>(?:(?:(?<![0-9.+-])(?>[+-]?(?:(?:[0-9]+(?:\.[0-9]+)?)|(?:\.[0-9]+)))))).*Account Name:\s*(?<username>[a-zA-Z0-9\.\-_]+).*ComputerName:\s*(?<hostname>[a-zA-Z0-9\.\-_]+).*Object Name:\s*(?<object_name>(?:[a-zA-Z]:)?(?:[^\\]+\\)*+).*
- 2025-03-03 00:08:43 -0800 [info]: fluent/log.rb:362:info: adding filter pattern="winevt.raw" type="record_transformer"
- 2025-03-03 00:08:43 -0800 [info]: fluent/log.rb:362:info: adding match pattern="winevt.raw" type="rewrite_tag_filter"
- 2025-03-03 00:08:43 -0800 [info]: #0 fluent/log.rb:362:info: adding rewrite_tag_filter rule: event_id [#<Fluent::PluginHelper::RecordAccessor::Accessor:0x000002219de64bf8 @keys="event_id">, /^(4660|4663|4656|4659)$/, "", "winevt.filtered", nil]
- 2025-03-03 00:08:43 -0800 [info]: fluent/log.rb:362:info: adding match pattern="winevt.filtered" type="loki"
- 2025-03-03 00:08:44 -0800 [info]: fluent/log.rb:362:info: adding source type="windows_eventlog2"
- 2025-03-03 00:08:44 -0800 [debug]: #0 fluent/log.rb:341:debug: No fluent logger for internal event
- 2025-03-03 00:08:44 -0800 [warn]: fluent/log.rb:383:warn: parameter 'remove_keys' in <match winevt.filtered>
- @type loki
- @id loki_output
- endpoint_url "http://192.168.1.2:3100/loki/api/v1/push"
- remove_keys event_id,handle_id
- <label>
- hostname ${hostname}
- username ${username}
- </label>
- <buffer>
- @type "file"
- path "C:/logs/buffer"
- flush_interval 5s
- </buffer>
- </match> is not used.
- 2025-03-03 00:08:44 -0800 [warn]: fluent/log.rb:383:warn: section <label> is not used in <match winevt.filtered> of loki plugin
- 2025-03-03 00:08:44 -0800 [warn]: fluent/log.rb:383:warn: section <label> is not used in <match winevt.filtered> of loki plugin
- 2025-03-03 00:08:44 -0800 [info]: #0 fluent/log.rb:362:info: starting fluentd worker pid=8116 ppid=6088 worker=0
- 2025-03-03 00:08:44 -0800 [debug]: #0 [loki_output] buffer started instance=4080 stage_size=0 queue_size=0
- 2025-03-03 00:08:44 -0800 [debug]: #0 [loki_output] flush_thread actually running
- 2025-03-03 00:08:44 -0800 [debug]: #0 [loki_output] enqueue_thread actually running
- 2025-03-03 00:08:44 -0800 [debug]: #0 [windows_eventlog2] channel (security) subscription is subscribed.
- 2025-03-03 00:08:44 -0800 [info]: #0 fluent/log.rb:362:info: fluentd worker is now running worker=0
- 2025-03-03 00:08:46 -0800 [info]: #0 fluent/log.rb:362:info: disable filter chain optimization because [Fluent::Plugin::ParserFilter, Fluent::Plugin::RecordTransformerFilter] uses `#filter_stream` method.
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement