fluent-plugin-windows-eventlog icon indicating copy to clipboard operation
fluent-plugin-windows-eventlog copied to clipboard

Add support to sysmon delimiters?

Open wolf1892 opened this issue 3 years ago • 1 comments

Parse_description, does not parse sysmon description::key. Cause the delimiter over there is specified by /r/n

Is it possible to have a support for sysmon, to parse_description?

wolf1892 avatar Oct 24 '22 04:10 wolf1892

I have a temporary working solution, hopefully something like this can be worked out? https://github.com/wolf1892/fluent-plugin-windows-eventlog/blob/master/lib/fluent/plugin/in_windows_eventlog2.rb

wolf1892 avatar Oct 24 '22 04:10 wolf1892