Best practices for the log shipper selection of Windows eventlog

Hi all,
currently I use OpenSearch with Logstash and Nxlog. Are there any best practices or recommendations on which log shipper is best to use?
I primarly want to use Security Analytics for Windows logs.

Hey @AME

I use both but for Windows I perfer Winlogbeat. Depend on how much room you have, Winlogbeat can get pretty chatty.

