A question about Winlogbeat configuration


(Jason) #1

Hello.
If I like below diagram:
Winlogbeat -> Logstash -> Elasticsearch -> Kibana

Then in Winlogbeat configuration I must set both Logstash and Elasticsearch servers?

Thank you.


(Andrew Kroh) #2

In that architecture you should configure Winlogbeat to output only to Logstash.


(Jason) #3

If I enabled "Elasticsearch" then what's happened?


(Andrew Kroh) #4

We don't recommend have two outputs enabled.

Winlogbeat will try to send the events directly to both Logstash and Elasticsearch. It requires a direct connection to both services. If one service goes down it will completely stop reporting events until it comes back up because it wants to guarantee at least once delivery to all outputs. Starting in 6.0 it does not allow you to have both outputs enabled at the same time.


(Jason) #5

"Winlogbeat will try to send the events directly to both Logstash and Elasticsearch" !!!
"Logstash and Elasticsearch" or "Logstash or Elasticsearch" ?
Thus I must disable "Logstash" or "Elasticsearch" ?


(system) #6

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.