To collect logs, Logmanager deploys centrally orchestrated agents on Windows servers and workstations. These agents forward events to the Logmanager instance for storage and further processing, while keeping deployment and configuration of log collection fast and simple. Each agent consists of two components: one collects Windows Event Logs (Winlogbeat) and the other gathers logs from text files (Filebeat).
As a result, the collected data is transformed into a well-structured database that operators can access through predefined customizable dashboards or by using structured and full-text searches.
See our documentation to learn how agents and Windows event log monitoring work in Logmanager.