{"id":19199396,"url":"https://github.com/supme/logevent","last_synced_at":"2026-06-03T16:31:08.900Z","repository":{"id":55917560,"uuid":"141401401","full_name":"Supme/logevent","owner":"Supme","description":"Windows log event metric for Prometheus textfile inputs","archived":false,"fork":false,"pushed_at":"2020-12-07T12:50:03.000Z","size":8,"stargazers_count":2,"open_issues_count":0,"forks_count":1,"subscribers_count":1,"default_branch":"master","last_synced_at":"2025-09-09T16:21:39.225Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":null,"language":"Go","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"mit","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/Supme.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":"Security.xml","support":null}},"created_at":"2018-07-18T07:58:21.000Z","updated_at":"2020-12-07T12:39:17.000Z","dependencies_parsed_at":"2022-08-15T09:20:50.674Z","dependency_job_id":null,"html_url":"https://github.com/Supme/logevent","commit_stats":null,"previous_names":[],"tags_count":2,"template":false,"template_full_name":null,"purl":"pkg:github/Supme/logevent","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/Supme%2Flogevent","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/Supme%2Flogevent/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/Supme%2Flogevent/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/Supme%2Flogevent/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/Supme","download_url":"https://codeload.github.com/Supme/logevent/tar.gz/refs/heads/master","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/Supme%2Flogevent/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":33874679,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-05-26T15:22:16.424Z","status":"online","status_checked_at":"2026-06-03T02:00:06.370Z","response_time":59,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":[],"created_at":"2024-11-09T12:27:01.995Z","updated_at":"2026-06-03T16:31:08.883Z","avatar_url":"https://github.com/Supme.png","language":"Go","funding_links":[],"categories":[],"sub_categories":[],"readme":"# Logevent\nWindows log event metric for Prometheus textfile inputs\n\nДля логирования неуспешных входов:\n - включить логирование плохих входов в windows через gpedit.msc\n   Local Computer Policy → Computer Configuration → Windows Settings → Security Settings → Local Policies → Audit Policy\n   \n   или по русски\n   \n   Политика \"Локальный компьютер\" → Конфигурация компьютера → Конфигурация Windows → Параметры безопасности → Локальные политики → Политика аудита\n   поставить обе галки в Audit logon events (Аудит входа в систему) и Audit account logon events (Аудит событий входа в систему)\n   \n - Скопировать logevent.exe в C:\\Program Files\\windows_exporter\\logevent.exe\n\n - В планировщике импортируем Security.xml (если это сделали, то следующий шаг пропускаем)\n \n - В планировщике заданий создаём задачу в \"Задачи просмотра событий\":\n   Имя \"Security\"\n   Выполнять с наивысшими правами\n   Выполнять вне зависимости от регистрации пользователя\n   Триггер создать:\n   - начать задачу: при событии\n   - при событии настраиваемое\n   - фильтр событий по журналу Журнал событий Журналы windows безопасность\n   - коды событий: 4625,5461,529,530,531,532,533,534,535,539\n   Действия:\n     Запуск программы:\n\t \"C:\\Program Files\\windows_exporter\\logevent.exe\" аргументы -m \"windows_logevent_bad_login_count\" -d \"Bad login event\"\n   Параметры:\n   - Останавливать задачу выполняемую дольше: 1ч.\n   - Если задача уже выполняется, то применять правило: Запускать новый экземпляр задания\n   \nУ windows-exporter должен быть включен коллектор textfile\n\nЗапрос в Prometheus примерно таков:\nincrease(windows_logevent_bad_login_count[5m])\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fsupme%2Flogevent","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fsupme%2Flogevent","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fsupme%2Flogevent/lists"}