How To Collect and Ship Windows Events Logs With OpenTelemetry

If you use Windows, you will want to monitor Windows Events. A recent contribution of a distribution of the OpenTelemetry (OTel) Collector makes it much easier to monitor Windows Events with OpenTel. You can utilize this receiver either in conjunction with any OTel collector: including the OpenTelemetry Collector. In this article, we will be using observIQ’s distribution of the collector. Below are steps to get up and running quickly with the distribution. We will be shipping Windows Event logs to a popular backend: Google Cloud Ops. You can find out more on the GitHub page here.

What Signals Matter?

Windows Events logs record many different operating system processes, application activity, and account activity. Some relevant log types you will want to monitor include:

CategoriesUncategorized