# Can not receive log from remote window machine

**URL:** https://discuss.elastic.co/t/can-not-receive-log-from-remote-window-machine/136963
**Category:** Logstash
**Created:** [June 22, 2018, 3:39am UTC](https://discuss.elastic.co/t/can-not-receive-log-from-remote-window-machine/136963 "2018-06-22T03:39:07Z")
**Posts on this page:** 3
**Page:** 1

<div class="post-metadata">

### Author: ![peterch](https://avatars.discourse-cdn.com/v4/letter/p/e5b9ba/32.png) [@peterch](https://discuss.elastic.co/u/peterch)
#### Post date: [June 22, 2018, 3:39am UTC](https://discuss.elastic.co/t/can-not-receive-log-from-remote-window-machine/136963/1 "2018-06-22T03:39:07Z")

</div>

Dear All,

I install winlogbeat in a remote window machine but cannot receive log from elk server. I check logstash log find following message. But I can receive other window machine log. May I know why?

Thanks

[2018-06-22T11:32:06,077][WARN][logstash.outputs.elasticsearch] Could not index event to Elasticsearch. {:status=\>400, :action=\>["index", {:\_id=\>nil, :\_index=\>"winlogbeat-2018.06.22", :\_type=\>"doc", :\_routing=\>nil}, #LogStash::Event:0x482ccb74], :response=\>{"index"=\>{"\_index"=\>"winlogbeat-2018.06.22", "\_type"=\>"doc", "\_id"=\>"GkSMJWQBe6ImA6Ysj88n", "status"=\>400, "error"=\>{"type"=\>"mapper\_parsing\_exception", "reason"=\>"failed to parse [host]", "caused\_by"=\>{"type"=\>"illegal\_state\_exception", "reason"=\>"Can't get text on a START\_OBJECT at 1:69"}}}}}

Best Regards,  
Peter

---

<div class="post-metadata">

### Author: ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)
#### Post date: [June 25, 2018, 9:56pm UTC](https://discuss.elastic.co/t/can-not-receive-log-from-remote-window-machine/136963/2 "2018-06-25T21:56:25Z")

</div>

> [@Logstash errors after upgrading to filebeat-6.3.0](https://discuss.elastic.co/t/logstash-errors-after-upgrading-to-filebeat-6-3-0/135984):
>
> After upgrading from filebeat-6.2.4 to filebeat-6.3.0 none of my log messages make into logstash. I did not make any filebeat.yml or logstash.conf changes during the upgrade. The logstash.stdout is full of errors like this... [2018-06-14T16:36:44,073][WARN][logstash.outputs.elasticsearch] Could not index event to Elasticsearch. {:status=\>400, :action=\>["index", {:\_id=\>nil, :\_index=\>"logstash-2018.06.14", :\_type=\>"doc", :\_routing=\>nil}, #\<LogStash::E vent:0x7915b5b2\>], :response=\>{"index"=\>{"…

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [July 23, 2018, 9:56pm UTC](https://discuss.elastic.co/t/can-not-receive-log-from-remote-window-machine/136963/3 "2018-07-23T21:56:28Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
