获取安装包
winlogbeat下载地址:https://www.elastic.co/cn/downloads/beats/winlogbeat
安装步骤
-
解压到d:\
-
以管理员身份打开PowerShell
-
进入winlogbeat解压后的目录:
cd d:\winlogbeat -
执行安装脚本
.\install-service-winlogbeat.ps1
注意: 如果在系统上禁用了脚本执行,则需要为当前会话设置执行策略以允许脚本运行。 PowerShell.exe -ExecutionPolicy UnRestricted -File .\install-service-winlogbeat.ps1
- 启动winlogbeat服务
Start-Service winlogbeat
停止wilogbeat服务
Stop-Service winlogbeat
卸载winlogbeat
.\uninstall-service-winlogbeat.ps1
安装脚本
winlogbeat_install1.bat
::直接双击运行该文件
::解压winlogbeat到d:\根目录中
@title install winlogbeat
set "rar=C:\Program Files\WinRAR\WinRAR.exe"
if exist winlogbeat.zip (
"%rar%" x -ad -y winlogbeat.zip d:\
)
@echo on
timeout /nobreak /t 10 >nul
winlogbeat_install2.bat
::以管理员身份运行此文件,winlogbeat安装在d:\winlogbeat中,如位置变化,请更改对应路径
@echo on
::进入winlogbeat所在的盘
d:
::进入winlogbeat安装目录
cd winlogbeat
::安装winlogbeat服务
Powershell.exe -ExecutionPolicy UnRestricted -File install-service-winlogbeat.ps1
::启动winlogbeat
Powershell.exe Start-Service winlogbeat
::停掉winlogbeat服务
::Powershell.exe Stop-Service winlogbeat
::卸载winlogbeat
::Powershell.exe -file uninstall-service-winlogbeat.ps1
timeout /nobreak /t 10 >nul
配置文件
winlogbeat.yml