Best practices for the log shipper selection of Windows eventlog

Hi all,
currently I use OpenSearch with Logstash and Nxlog. Are there any best practices or recommendations on which log shipper is best to use?
I primarly want to use Security Analytics for Windows logs.
Thx

Hey @AME

I use both but for Windows I perfer Winlogbeat. Depend on how much room you have, Winlogbeat can get pretty chatty.

1 Like

Hi Ame!
I have question how are you using Logstash in Windows?
I mean there are no Logstash for Windows - Only for Linux and MacOs

I guess, he uses this version of Logstash…?