<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Re: How to send Windows event log to HCP ? in Archives of Support Questions (Read Only)</title>
    <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/How-to-send-Windows-event-log-to-HCP/m-p/241283#M85875</link>
    <description>&lt;P&gt;Hi &lt;A rel="user" href="https://community.cloudera.com/users/97908/hacofayik.html" nodeid="97908"&gt;@haco fayik&lt;/A&gt;&lt;/P&gt;&lt;P&gt;That looks great. Sounds like you got around the initial problem of ingesting data into Metron.&lt;/P&gt;&lt;P&gt;There could be multiple reasons, e.g. parser, enrichment and indexing topologies not running or being misconfigured.&lt;/P&gt;&lt;P&gt;Would you create a new question for this and provide more details, such as worker logs of those topologies?&lt;/P&gt;&lt;P&gt;Would you also mark the answer that helped you most solve the ingest problem as "Best Answer"?&lt;/P&gt;&lt;P&gt;thanks!&lt;/P&gt;</description>
    <pubDate>Mon, 07 Jan 2019 20:27:39 GMT</pubDate>
    <dc:creator>StefanDunkler</dc:creator>
    <dc:date>2019-01-07T20:27:39Z</dc:date>
    <item>
      <title>How to send Windows event log to HCP ?</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/How-to-send-Windows-event-log-to-HCP/m-p/241277#M85869</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;I want to send Windows event log to HCP ( with any agent like winlogbeats or etc ) but I don't know how to do this ? can you provide solution ?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Fri, 16 Sep 2022 14:01:22 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/How-to-send-Windows-event-log-to-HCP/m-p/241277#M85869</guid>
      <dc:creator>hacofayik</dc:creator>
      <dc:date>2022-09-16T14:01:22Z</dc:date>
    </item>
    <item>
      <title>Re: How to send Windows event log to HCP ?</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/How-to-send-Windows-event-log-to-HCP/m-p/241278#M85870</link>
      <description>&lt;P&gt;Hi &lt;A rel="user" href="https://community.cloudera.com/users/97908/hacofayik.html" nodeid="97908"&gt;@haco fayik&lt;/A&gt;,&lt;/P&gt;&lt;P&gt;as a starting point you need to push data into a parser specific Kafka topic (you can call the topic "windows-event-log"), and configure a parser in the Metron Management UI and start it. In the parser configuration you configure Metron, from which Kafka topic the messages are picked up ("windows-event-log" in our case) and how to parse the incoming messages.&lt;/P&gt;&lt;P&gt;NiFi is a great tool to collect data from various sources and push it into Kafka.&lt;/P&gt;&lt;P&gt;Maybe my article helps you: &lt;A href="https://datahovel.com/2018/07/18/how-to-onboard-a-new-data-source-in-apache-metron/" target="_blank"&gt;https://datahovel.com/2018/07/18/how-to-onboard-a-new-data-source-in-apache-metron/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;If you have more specific questions, don't hesitate to ask!&lt;/P&gt;</description>
      <pubDate>Mon, 31 Dec 2018 16:44:03 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/How-to-send-Windows-event-log-to-HCP/m-p/241278#M85870</guid>
      <dc:creator>StefanDunkler</dc:creator>
      <dc:date>2018-12-31T16:44:03Z</dc:date>
    </item>
    <item>
      <title>Re: How to send Windows event log to HCP ?</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/How-to-send-Windows-event-log-to-HCP/m-p/241279#M85871</link>
      <description>&lt;P&gt;hi &lt;A rel="user" href="https://community.cloudera.com/users/17971/sdunkler.html" nodeid="17971"&gt;@Stefan Kupstaitis-Dunkler&lt;/A&gt;, &lt;/P&gt;&lt;P&gt;Thank you so much for your answer ,&lt;/P&gt;&lt;P&gt;if I have 5 windows server and workstation , I should install nifi on each host  or I can use one nifi server for all hosts ?&lt;/P&gt;&lt;P&gt; How to send data ( event log) to nifi ?&lt;/P&gt;</description>
      <pubDate>Mon, 31 Dec 2018 20:33:05 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/How-to-send-Windows-event-log-to-HCP/m-p/241279#M85871</guid>
      <dc:creator>hacofayik</dc:creator>
      <dc:date>2018-12-31T20:33:05Z</dc:date>
    </item>
    <item>
      <title>Re: How to send Windows event log to HCP ?</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/How-to-send-Windows-event-log-to-HCP/m-p/241280#M85872</link>
      <description>&lt;P&gt;&lt;A href="https://community.hortonworks.com/questions/232177/how-to-send-windows-event-log-to-hcp.html?childToView=232193#"&gt;@haco fayik&lt;/A&gt;&lt;/P&gt;&lt;P&gt;There's many ways to do this. &lt;EM&gt;You should probably search this community in the NiFi section or get familiar with NiFi in general.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;However, as a a short overview, the most common cases for Metron ingestion, I'm encountering in the field are:&lt;/P&gt;&lt;UL&gt;
&lt;LI&gt;your sources are pushing the message to a &lt;STRONG&gt;&lt;EM&gt;syslog&lt;/EM&gt;&lt;/STRONG&gt; server. You can configure your syslog server to push data to your NiFi instance over TCP or UDP. In this case you'd need a "ListenSyslog" processor and a "PublishKafka" processor.&lt;/LI&gt;&lt;LI&gt;you already have a log forwarder capable of pushing data to Kafka (&lt;STRONG&gt;&lt;EM&gt;winlogbeats&lt;/EM&gt;&lt;/STRONG&gt;&lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt; &lt;A href="https://www.elastic.co/guide/en/beats/winlogbeat/current/configuring-output.html" target="_blank"&gt;https://www.elastic.co/guide/en/beats/winlogbeat/current/configuring-output.html&lt;/A&gt; . In this case you won't need NiFi, if you are comfortable using winlogbeats.&lt;/LI&gt;&lt;LI&gt;You install &lt;EM&gt;&lt;STRONG&gt;MiNiFi&lt;/STRONG&gt;&lt;/EM&gt; on all servers to act as a simple log forwarder over tcp. You'd send those packets to a NiFi instance/cluster (similar to the Syslog approach), receive them via "ListenTcp" processor and push your messages into Kafka using the "PublishKafka" processor. You could also send data directly into Kafka from MiNiFi.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Note: If your Kafka cluster is secured with Kerberos, this might influence your choice.&lt;/P&gt;</description>
      <pubDate>Mon, 31 Dec 2018 20:59:59 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/How-to-send-Windows-event-log-to-HCP/m-p/241280#M85872</guid>
      <dc:creator>StefanDunkler</dc:creator>
      <dc:date>2018-12-31T20:59:59Z</dc:date>
    </item>
    <item>
      <title>Re: How to send Windows event log to HCP ?</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/How-to-send-Windows-event-log-to-HCP/m-p/241281#M85873</link>
      <description>&lt;P&gt;thank you very much &lt;A rel="user" href="https://community.cloudera.com/users/17971/sdunkler.html" nodeid="17971"&gt;@Stefan Kupstaitis-Dunkler&lt;/A&gt; &lt;/P&gt;</description>
      <pubDate>Tue, 01 Jan 2019 19:33:58 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/How-to-send-Windows-event-log-to-HCP/m-p/241281#M85873</guid>
      <dc:creator>hacofayik</dc:creator>
      <dc:date>2019-01-01T19:33:58Z</dc:date>
    </item>
    <item>
      <title>Re: How to send Windows event log to HCP ?</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/How-to-send-Windows-event-log-to-HCP/m-p/241282#M85874</link>
      <description>&lt;P&gt;Hi &lt;A rel="user" href="https://community.cloudera.com/users/17971/sdunkler.html" nodeid="17971" target="_blank"&gt;@Stefan Kupstaitis-Dunkler&lt;/A&gt;&lt;/P&gt;&lt;P&gt;I Installed winlogbeats on Windows workstation with below config :&lt;/P&gt;&lt;PRE&gt;output.logstash:
  hosts: ["nifi.node.srv:5098"]&lt;/PRE&gt;&lt;P&gt;and I use this nifi processors to stream event to metron &lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="97533-nifi1.png" style="width: 1102px;"&gt;&lt;img src="https://community.cloudera.com/t5/image/serverpage/image-id/13752i8ADA38FEECEEE5BB/image-size/medium?v=v2&amp;amp;px=400" role="button" title="97533-nifi1.png" alt="97533-nifi1.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;listenbeats config :&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="97534-nifi2.png" style="width: 796px;"&gt;&lt;img src="https://community.cloudera.com/t5/image/serverpage/image-id/13753iE0AAA5FBC2F78D04/image-size/medium?v=v2&amp;amp;px=400" role="button" title="97534-nifi2.png" alt="97534-nifi2.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Publishkafka cofig :&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="97535-nifi3.png" style="width: 791px;"&gt;&lt;img src="https://community.cloudera.com/t5/image/serverpage/image-id/13754i2F7C387D8130C915/image-size/medium?v=v2&amp;amp;px=400" role="button" title="97535-nifi3.png" alt="97535-nifi3.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Nifi Data provenance in publishkafka processor :&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="97536-nifi4.png" style="width: 1406px;"&gt;&lt;img src="https://community.cloudera.com/t5/image/serverpage/image-id/13755i994CF74FD32601E9/image-size/medium?v=v2&amp;amp;px=400" role="button" title="97536-nifi4.png" alt="97536-nifi4.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;and I create sensor in Management UI with logstash parser and winlogtop topic ( kafka) . now I can't see any log data in alert UI . what's problem ?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Sat, 17 Aug 2019 22:17:51 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/How-to-send-Windows-event-log-to-HCP/m-p/241282#M85874</guid>
      <dc:creator>hacofayik</dc:creator>
      <dc:date>2019-08-17T22:17:51Z</dc:date>
    </item>
    <item>
      <title>Re: How to send Windows event log to HCP ?</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/How-to-send-Windows-event-log-to-HCP/m-p/241283#M85875</link>
      <description>&lt;P&gt;Hi &lt;A rel="user" href="https://community.cloudera.com/users/97908/hacofayik.html" nodeid="97908"&gt;@haco fayik&lt;/A&gt;&lt;/P&gt;&lt;P&gt;That looks great. Sounds like you got around the initial problem of ingesting data into Metron.&lt;/P&gt;&lt;P&gt;There could be multiple reasons, e.g. parser, enrichment and indexing topologies not running or being misconfigured.&lt;/P&gt;&lt;P&gt;Would you create a new question for this and provide more details, such as worker logs of those topologies?&lt;/P&gt;&lt;P&gt;Would you also mark the answer that helped you most solve the ingest problem as "Best Answer"?&lt;/P&gt;&lt;P&gt;thanks!&lt;/P&gt;</description>
      <pubDate>Mon, 07 Jan 2019 20:27:39 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/How-to-send-Windows-event-log-to-HCP/m-p/241283#M85875</guid>
      <dc:creator>StefanDunkler</dc:creator>
      <dc:date>2019-01-07T20:27:39Z</dc:date>
    </item>
    <item>
      <title>Re: How to send Windows event log to HCP ?</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/How-to-send-Windows-event-log-to-HCP/m-p/241284#M85876</link>
      <description>&lt;P&gt;Thanks &lt;A rel="user" href="https://community.cloudera.com/users/17971/sdunkler.html" nodeid="17971"&gt;@Stefan Kupstaitis-Dunkler,&lt;BR /&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;I marked best answer and I will create a new question for this problem . Can you provide location of these log file?&lt;/P&gt;&lt;P&gt;I confused that Can I use metron for Collect windows and linux hosts and network devices log for security purpose ? ( Threat detection and etc)&lt;/P&gt;&lt;P&gt;Please accept my thanks for your helps&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;A rel="user" href="https://community.cloudera.com/users/17971/sdunkler.html" nodeid="17971"&gt;&lt;/A&gt; &lt;/P&gt;</description>
      <pubDate>Tue, 08 Jan 2019 16:43:49 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/How-to-send-Windows-event-log-to-HCP/m-p/241284#M85876</guid>
      <dc:creator>hacofayik</dc:creator>
      <dc:date>2019-01-08T16:43:49Z</dc:date>
    </item>
  </channel>
</rss>

