You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何使用Fluentd转发Windows Sysmon日志?已能转发应用、安全及系统日志但缺少Sysmon日志配置指引

解决Fluentd转发Sysmon日志的问题

没问题,我帮你搞定这个Sysmon日志转发的配置!

你当前的配置只覆盖了Windows默认的三个日志通道,而Sysmon的日志属于自定义事件日志通道,需要在windows_eventlog2插件里明确指定它的完整通道名称才能被采集到。

关键修改点

Sysmon对应的Windows事件日志通道名称是:Microsoft-Windows-Sysmon/Operational,你只需要把这个通道添加到source配置的channels参数里即可。

修改后的完整配置

<source>
  @type windows_eventlog2
  @id windows_eventlog2
  channels application,system,security,Microsoft-Windows-Sysmon/Operational
  tag system
  render_as_xml true
  <storage>
    persistent false
  </storage>
  parse_description false
  read_existing_events false
</source>
<match system.**>
  @type kinesis_firehose
  region xxx
  delivery_stream_name xxx
  aws_key_id xxx
  aws_sec_key xxx
  <assume_role_credentials>
    duration_seconds 3600
    role_arn xxx
    role_session_name "xxx"
  </assume_role_credentials>
  <format>
    @type json
  </format>
</match>

额外注意事项

  • 权限检查:确保运行Fluentd服务的Windows用户拥有读取Microsoft-Windows-Sysmon/Operational日志的权限,默认管理员权限是没问题的,但如果用普通用户运行,需要手动配置日志读取权限。
  • 历史日志采集:如果需要转发之前已经生成的Sysmon日志,可以把read_existing_events改成true,这样Fluentd会先读取历史日志,之后再持续采集新日志。
  • 通道名称验证:你可以在Windows事件查看器里确认通道名称是否正确——找到Sysmon日志后,右键查看“属性”,里面的“全名”就是我们需要的通道名。

内容的提问来源于stack exchange,提问作者ryan corner

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.27 15:13:15