Projects08 Infrastructure
Windows Open-Source Log Monitoring
Windows event and application logs collected, enriched, stored in Loki, and alerted from Grafana.
Problem
Windows event and application logs were hard to collect, label, and alert on without staying on a vendor monitoring stack.
Solution
Built an open-source path from Windows hosts through collection and enrichment into Loki, with Grafana dashboards and alerts on the events that matter.
Architecture
- Windows hosts
- Collector
- Enrichment
- Loki
- Grafana
- Alerting
Technology
- Windows Event Logs
- Vector
- Fluent Bit
- Loki
- Grafana
Engineering decisions
- Event volume that will drown a backend if every channel is shipped raw.
- Dropping noise without hiding the security-sensitive events.
- Labels that stay useful in LogQL instead of becoming a dump of every field.
- Collectors that keep running across a reboot and a stalled output.
Automation
Host onboarding applies the same collector config, pipelines, and alert rules instead of a one-off agent install.
Reliability
The collector buffers when Loki is slow and resumes without dropping the window of events operators care about.
Security
Security-sensitive channels are kept; credentials and personal data are stripped or hashed before they leave the host.