# Can I ingest specific log files using winlogbeat?

**URL:** <https://discuss.elastic.co/t/can-i-ingest-specific-log-files-using-winlogbeat/303124>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [April 25, 2022, 7:41am UTC](https://discuss.elastic.co/t/can-i-ingest-specific-log-files-using-winlogbeat/303124 "2022-04-25T07:41:30Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![rrrrrrrrrrr](https://avatars.discourse-cdn.com/v4/letter/r/50afbb/32.png) [@rrrrrrrrrrr](https://discuss.elastic.co/u/rrrrrrrrrrr)\
**Post date:** [April 25, 2022, 7:41am UTC](https://discuss.elastic.co/t/can-i-ingest-specific-log-files-using-winlogbeat/303124/1 "2022-04-25T07:41:30Z")

</div>

Hello,

I would just like to ask if I can ingest a specific logfile using Winlogbeat?

If yes, can you provide a structure or link how to do it since I tried researching and no luck finding an answer.

Right now here's my Winlogbeat Specific Options setting

```auto
# ======================== Winlogbeat specific options =========================

# event_logs specifies a list of event logs to monitor as well as any
# accompanying options. The YAML data type of event_logs is a list of
# dictionaries.
#
# The supported keys are name (required), tags, fields, fields_under_root,
# forwarded, ignore_older, level, event_id, provider, and include_xml. Please
# visit the documentation for the complete details of each option.
# https://go.es.io/WinlogbeatConfig

winlogbeat.event_logs:
  - name: Application
    ignore_older: 72h

  - name: System

  - name: Security
    processors:
      - script:
          lang: javascript
          id: security
          file: ${path.home}/module/security/config/winlogbeat-security.js

  - name: Microsoft-Windows-Sysmon/Operational
    processors:
      - script:
          lang: javascript
          id: sysmon
          file: ${path.home}/module/sysmon/config/winlogbeat-sysmon.js

  - name: Windows PowerShell
    event_id: 400, 403, 600, 800
    processors:
      - script:
          lang: javascript
          id: powershell
          file: ${path.home}/module/powershell/config/winlogbeat-powershell.js

  - name: Microsoft-Windows-PowerShell/Operational
    event_id: 4103, 4104, 4105, 4106
    processors:
      - script:
          lang: javascript
          id: powershell
          file: ${path.home}/module/powershell/config/winlogbeat-powershell.js

  - name: ForwardedEvents
    tags: [forwarded]
    processors:
      - script:
          when.equals.winlog.channel: Security
          lang: javascript
          id: security
          file: ${path.home}/module/security/config/winlogbeat-security.js
      - script:
          when.equals.winlog.channel: Microsoft-Windows-Sysmon/Operational
          lang: javascript
          id: sysmon
          file: ${path.home}/module/sysmon/config/winlogbeat-sysmon.js
      - script:
          when.equals.winlog.channel: Windows PowerShell
          lang: javascript
          id: powershell
          file: ${path.home}/module/powershell/config/winlogbeat-powershell.js
      - script:
          when.equals.winlog.channel: Microsoft-Windows-PowerShell/Operational
          lang: javascript
          id: powershell
          file: ${path.home}/module/powershell/config/winlogbeat-powershell.js

```

Sorry I'm just a newbie in ELK.  
Thank you.

---

<div class="post-metadata">

**Author:** ![grfneto](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/grfneto/32/125776_2.png) [@grfneto](https://discuss.elastic.co/u/grfneto)\
**Post date:** [April 25, 2022, 2:50pm UTC](https://discuss.elastic.co/t/can-i-ingest-specific-log-files-using-winlogbeat/303124/2 "2022-04-25T14:50:14Z")

</div>

Hi @rrrrrrrrrrr

Welcome to the community. winlogbeat is a specific agent for capturing windows logs. If you want logs from a specific application, you can use filebeat by setting the path of the log you want to collect.

[Configure project paths | Filebeat Reference [8.1] | Elastic](https://www.elastic.co/guide/en/beats/filebeat/current/configuration-path.html)

Best regards

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [April 26, 2022, 12:58am UTC](https://discuss.elastic.co/t/can-i-ingest-specific-log-files-using-winlogbeat/303124/3 "2022-04-26T00:58:41Z")

</div>

Welcome to our community! 😃 Also, please don't use all caps in topic titles.

Definitely use Filebeat for this, not Winlogbeat.

---

<div class="post-metadata">

**Author:** ![rrrrrrrrrrr](https://avatars.discourse-cdn.com/v4/letter/r/50afbb/32.png) [@rrrrrrrrrrr](https://discuss.elastic.co/u/rrrrrrrrrrr)\
**Post date:** [April 26, 2022, 9:29am UTC](https://discuss.elastic.co/t/can-i-ingest-specific-log-files-using-winlogbeat/303124/4 "2022-04-26T09:29:19Z")

</div>

Apologies for the title. Thank you for your answer 😇

---

<div class="post-metadata">

**Author:** ![rrrrrrrrrrr](https://avatars.discourse-cdn.com/v4/letter/r/50afbb/32.png) [@rrrrrrrrrrr](https://discuss.elastic.co/u/rrrrrrrrrrr)\
**Post date:** [April 26, 2022, 9:31am UTC](https://discuss.elastic.co/t/can-i-ingest-specific-log-files-using-winlogbeat/303124/5 "2022-04-26T09:31:02Z")

</div>

Thank you for explaining this to me. I just thought that Its possible but yea, your answer makes sense since I'm also using filebeat for another application. 👏

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 24, 2022, 11:31am UTC](https://discuss.elastic.co/t/can-i-ingest-specific-log-files-using-winlogbeat/303124/6 "2022-05-24T11:31:51Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
