# Beats log capture limitation using filebeat, matricbeat and winlogbeat

**URL:** <https://discuss.elastic.co/t/beats-log-capture-limitation-using-filebeat-matricbeat-and-winlogbeat/244542>\
**Category:** Beats\
**Tags:** filebeat, metricbeat, winlogbeat\
**Created:** [August 11, 2020, 11:54am UTC](https://discuss.elastic.co/t/beats-log-capture-limitation-using-filebeat-matricbeat-and-winlogbeat/244542 "2020-08-11T11:54:40Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![japarka2](https://avatars.discourse-cdn.com/v4/letter/j/3e96dc/32.png) [@japarka2](https://discuss.elastic.co/u/japarka2)\
**Post date:** [August 11, 2020, 11:54am UTC](https://discuss.elastic.co/t/beats-log-capture-limitation-using-filebeat-matricbeat-and-winlogbeat/244542/1 "2020-08-11T11:54:40Z")

</div>

Hi Team,

Since I am new to Beats and ElasticSearch, I have few query before perfromaing POC on Beats and Elasticsearch for windows and Linux monitoring.  
Is possible to capature the log on endpoint and send the capture log at sechdule time to save network bandwidth instead of sending data continuously to Elasticsearch for alerting ?  
If yes how much log can be stored locally before sending to logtrash/ElasticSearch ?  
As well as share the method to store logs to endpoint and send to centeral monitoring system for alerting and ticketing.

Thanks & Regards  
Jai Parkash

---

<div class="post-metadata">

**Author:** ![kvch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kvch/32/72058_2.png) [@kvch](https://discuss.elastic.co/u/kvch)\
**Post date:** [August 11, 2020, 2:17pm UTC](https://discuss.elastic.co/t/beats-log-capture-limitation-using-filebeat-matricbeat-and-winlogbeat/244542/2 "2020-08-11T14:17:06Z")

</div>

Unfortunately, it is not supported by Filebeat.

---

<div class="post-metadata">

**Author:** ![japarka2](https://avatars.discourse-cdn.com/v4/letter/j/3e96dc/32.png) [@japarka2](https://discuss.elastic.co/u/japarka2)\
**Post date:** [August 11, 2020, 5:59pm UTC](https://discuss.elastic.co/t/beats-log-capture-limitation-using-filebeat-matricbeat-and-winlogbeat/244542/3 "2020-08-11T17:59:35Z")

</div>

will it work if we put the logtash in between filebeat and elastic search.  
like bastion host in case of network connectivity between your private network server on public cloud.  
kindly brief the usages of logtash to complete this issues

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 8, 2020, 7:59pm UTC](https://discuss.elastic.co/t/beats-log-capture-limitation-using-filebeat-matricbeat-and-winlogbeat/244542/4 "2020-09-08T19:59:39Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
