At the moment i'm able to retrieve logs from the Windows Eventviewer with a specific eventID into Zabbix with Agent2.
The log result has multiple lines. I would like to use only some specific lines from the result like "Account Name" and "Client Address".
Can someone guide me how this can be done?
An example of a log file:
Kerberos pre-authentication failed.
Account Information:
Security ID: DOMAIN\LAPTOP$
Account Name: LAPTOP$
Service Information:
Service Name: krbtgt/DOMAIN.COM
Network Information:
Client Address: 192.168.10.20
Client Port: 58412
The log result has multiple lines. I would like to use only some specific lines from the result like "Account Name" and "Client Address".
Can someone guide me how this can be done?
An example of a log file:
Kerberos pre-authentication failed.
Account Information:
Security ID: DOMAIN\LAPTOP$
Account Name: LAPTOP$
Service Information:
Service Name: krbtgt/DOMAIN.COM
Network Information:
Client Address: 192.168.10.20
Client Port: 58412
Comment