---
isPrivate: true
title: Exabeam - Windows
description: Learn more about the Exabeam - Windows pack.
breadcrumbs: Docs > Observability Pipelines > Packs > Exabeam - Windows
---

> For the complete documentation index, see [llms.txt](https://docs.datadoghq.com/llms.txt).

# Exabeam - Windows

{% callout %}
# Important note for users on the following Datadog sites: app.ddog-gov.com, us2.ddog-gov.com

{% alert level="danger" %}
This product is not supported for your selected [Datadog site](https://docs.datadoghq.com/getting_started/site.md). ({% placeholder "user-datadog-site-name" /%}).
{% /alert %}

{% /callout %}

## Overview{% #overview %}

{% image
   source="https://docs.dd-static.net/images/observability_pipelines/packs/exabeam_windows.f520fee293bc881670e37dd04536ee02.png?auto=format&fit=max&w=850 1x, https://docs.dd-static.net/images/observability_pipelines/packs/exabeam_windows.f520fee293bc881670e37dd04536ee02.png?auto=format&fit=max&w=850&dpr=2 2x"
   alt="The Exabeam - Windows pack" /%}

This pack processes Windows Event Logs sent to Exabeam and filters to codes Exabeam parsers use, keeping raw XML intact for parsing.

What this pack does:

- Keeps raw XML intact
- Keeps Sysmon and PowerShell logs
- Drops unused Security codes
