# Can what types of logs are taken from winlogbeat

**URL:** <https://discuss.elastic.co/t/can-what-types-of-logs-are-taken-from-winlogbeat/163885>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [January 11, 2019, 10:54am UTC](https://discuss.elastic.co/t/can-what-types-of-logs-are-taken-from-winlogbeat/163885 "2019-01-11T10:54:46Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Dv\_Thiyanesh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dv_thiyanesh/32/53965_2.png) [@Dv\_Thiyanesh](https://discuss.elastic.co/u/Dv_Thiyanesh)\
**Post date:** [January 11, 2019, 10:54am UTC](https://discuss.elastic.co/t/can-what-types-of-logs-are-taken-from-winlogbeat/163885/1 "2019-01-11T10:54:46Z")

</div>

I have doubt i have to take logs from one windows machine main criteria is I want a log that has information URL Access and use drive access and print access  
for that i want use which types of beat either winlogbeat is enough or filebeat

1. i have used winlogbeat but it gives only the information about booting and os information  
but i need the logs of those?  
what can i do?

2. i one scenario we have 100 client and it has beat from that client we take the log and send it to only one logstash on a server machine doing this the network gets slow it send huge logs for that we can take the specific log from the machine using beat?  
there is any idea about it?

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [January 18, 2019, 10:32pm UTC](https://discuss.elastic.co/t/can-what-types-of-logs-are-taken-from-winlogbeat/163885/2 "2019-01-18T22:32:51Z")

</div>

> [@Dv\_Thiyanesh](#):
>
> i have used winlogbeat but it gives only the information about booting and os information  
> but i need the logs of those?  
> what can i do?

There are many different Windows event logs providing all kinds of details about what the operating system and users are doing. Some of those logs may require additional GPO settings to enable more detailed audit logging. If you want anything more than the events from the `Application`, `System`, and `Security` event logs then you must add those logs to your Winlogbeat configuration file.

Beyond what Windows natively writes to the event logs, there are tools such as [Sysmon](https://docs.microsoft.com/en-us/sysinternals/downloads/sysmon) that collect great deal of information about the system and write it to an event logs. You can then use Winlogbeat to collect these events.

You'll need to research the event logs to see if there are events reported for the specific actions that you are interested in. If you can provide more details about what you want to monitor I can see if I can find anything.

> [@Dv\_Thiyanesh](#):
>
> i one scenario we have 100 client and it has beat from that client we take the log and send it to only one logstash on a server machine doing this the network gets slow it send huge logs for that we can take the specific log from the machine using beat?

I don't fully understand this question. You can apply filters on Winlogbeat side to limit the events that are sent to LS. You can also run more than LS instance and configure Winlogbeat to load balance between them. Or you can front the LS instances with a TCP load balancer.

---

<div class="post-metadata">

**Author:** ![Dv\_Thiyanesh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dv_thiyanesh/32/53965_2.png) [@Dv\_Thiyanesh](https://discuss.elastic.co/u/Dv_Thiyanesh)\
**Post date:** [January 23, 2019, 2:21pm UTC](https://discuss.elastic.co/t/can-what-types-of-logs-are-taken-from-winlogbeat/163885/3 "2019-01-23T14:21:33Z")

</div>

what is Meant by logstash intsance?

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [January 27, 2019, 4:22pm UTC](https://discuss.elastic.co/t/can-what-types-of-logs-are-taken-from-winlogbeat/163885/4 "2019-01-27T16:22:51Z")

</div>

One server running Logstash.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 24, 2019, 4:23pm UTC](https://discuss.elastic.co/t/can-what-types-of-logs-are-taken-from-winlogbeat/163885/5 "2019-02-24T16:23:01Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
