Armor Agent - Collecting Linux and Windows Standard Logs
Use the following commands to manage the Logging service - Filebeat and Winlogbeat (for Windows only).
Install Logging:
Windows: C:\.armor\opt\armor.exe logging install Linux: /opt/armor/armor logging install
Uninstall Logging:
Windows: C:\.armor\opt\armor.exe logging uninstall Linux: /opt/armor/armor logging uninstall
Logging Help
Windows: C:\.armor\opt\armor.exe logging help Linux: /opt/armor/armor logging help
Armor Agent - Collecting Custom Windows System Event Logs
Add new paths to filebeat config
C:\.armor\opt\armor.exe logging add-file-paths <paths to file locations>
Remove paths from filebeat config
C:\.armor\opt\armor.exe logging remove-file-paths <paths to file locations>
List added config paths
C:\.armor\opt\armor.exe logging describe-file-paths
Sync filebeat config
C:\.armor\opt\armor.exe logging sync-file-paths
Add winlogbeat event logs
C:\.armor\opt\armor.exe logging add-event-logs <add events>
Remove winlogbeat event logs
C:\.armor\opt\armor.exe logging remove-event-logs <add events>
List Event logs
C:\.armor\opt\armor.exe logging describe-event-logs
Sync event logs
C:\.armor\opt\armor.exe logging sync-event-logs