Skip to content
Srikanta Sahu

Projects08 Infrastructure

Windows Open-Source Log Monitoring

Windows event and application logs collected, enriched, stored in Loki, and alerted from Grafana.

Problem

Windows event and application logs were hard to collect, label, and alert on without staying on a vendor monitoring stack.

Solution

Built an open-source path from Windows hosts through collection and enrichment into Loki, with Grafana dashboards and alerts on the events that matter.

Architecture

  1. Windows hosts
  2. Collector
  3. Enrichment
  4. Loki
  5. Grafana
  6. Alerting

Technology

  • Windows Event Logs
  • Vector
  • Fluent Bit
  • Loki
  • Grafana

Engineering decisions

  • Event volume that will drown a backend if every channel is shipped raw.
  • Dropping noise without hiding the security-sensitive events.
  • Labels that stay useful in LogQL instead of becoming a dump of every field.
  • Collectors that keep running across a reboot and a stalled output.

Automation

Host onboarding applies the same collector config, pipelines, and alert rules instead of a one-off agent install.

Reliability

The collector buffers when Loki is slow and resumes without dropping the window of events operators care about.

Security

Security-sensitive channels are kept; credentials and personal data are stripped or hashed before they leave the host.