# Cannot start service winlogbeat in Docker Windows Container

**URL:** <https://discuss.elastic.co/t/cannot-start-service-winlogbeat-in-docker-windows-container/190092>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [July 11, 2019, 6:44pm UTC](https://discuss.elastic.co/t/cannot-start-service-winlogbeat-in-docker-windows-container/190092 "2019-07-11T18:44:04Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![HippyCraig](https://avatars.discourse-cdn.com/v4/letter/h/ccd318/32.png) [@HippyCraig](https://discuss.elastic.co/u/HippyCraig)\
**Post date:** [July 11, 2019, 6:44pm UTC](https://discuss.elastic.co/t/cannot-start-service-winlogbeat-in-docker-windows-container/190092/1 "2019-07-11T18:44:04Z")

</div>

I have looked through all the existing posts on this but I am still struggling with getting the service to run.

I am using Chocolaty to install winlogbeat inside my windows container, (1809). Everything install fine, I can run it directly from the command line in the container but the service doesn't start. I get error saying that it couldn't start from the command line and looking at the logs it shows it couldn't start in a timely manner and quits.

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [July 18, 2019, 4:26pm UTC](https://discuss.elastic.co/t/cannot-start-service-winlogbeat-in-docker-windows-container/190092/2 "2019-07-18T16:26:13Z")

</div>

I haven't used Windows containers, but running the service sounds like the wrong approach. Normally (at least with Linux) you want the ENTRYPOINT or CMD to directly execute the beat process and keep running. Like

`CMD .\winlogbeat.exe -e`

Could that work?

---

<div class="post-metadata">

**Author:** ![HippyCraig](https://avatars.discourse-cdn.com/v4/letter/h/ccd318/32.png) [@HippyCraig](https://discuss.elastic.co/u/HippyCraig)\
**Post date:** [July 22, 2019, 1:58pm UTC](https://discuss.elastic.co/t/cannot-start-service-winlogbeat-in-docker-windows-container/190092/3 "2019-07-22T13:58:22Z")

</div>

Thanks but , I am looking for the proper way to run this on a windows container. The installer works fine it creates the service it just wont start. If i run the same thing from a command line it works fine. Even if the proper way is to run it as a process I would still like to understand why the service doesn't start.

Sorry for the delay in responding I was away on vacation

I want to establish a best practice for windows containers at my company so I am hoping to get an official stance on the above.

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [July 22, 2019, 3:39pm UTC](https://discuss.elastic.co/t/cannot-start-service-winlogbeat-in-docker-windows-container/190092/4 "2019-07-22T15:39:14Z")

</div>

> [@HippyCraig](#):
>
> Thanks but , I am looking for the proper way to run this on a windows container.

I am suggesting that the right way is to set the ENTRYPOINT or CMD as winlogbeat.exe and not to use a service manager from within a container. When you run an application in a container, Docker monitors the active process in the container. If the active process (PID=1) stops, the container exits.

This also ensures that logs from the process are directly available via `docker logs`.

---

<div class="post-metadata">

**Author:** ![HippyCraig](https://avatars.discourse-cdn.com/v4/letter/h/ccd318/32.png) [@HippyCraig](https://discuss.elastic.co/u/HippyCraig)\
**Post date:** [July 22, 2019, 4:36pm UTC](https://discuss.elastic.co/t/cannot-start-service-winlogbeat-in-docker-windows-container/190092/5 "2019-07-22T16:36:31Z")

</div>

great thanks im new to containers so this is helpful. Just for curiosity sake services also get a PID is this not the case with containers? and i guess I am still curious as to why the service didnt start? there wastn any logs in winlogbeat created but I only found vague info in the event logs and cryptic errors when starting the service in powershell

---

<div class="post-metadata">

**Author:** ![HippyCraig](https://avatars.discourse-cdn.com/v4/letter/h/ccd318/32.png) [@HippyCraig](https://discuss.elastic.co/u/HippyCraig)\
**Post date:** [July 30, 2019, 12:22pm UTC](https://discuss.elastic.co/t/cannot-start-service-winlogbeat-in-docker-windows-container/190092/6 "2019-07-30T12:22:17Z")

</div>

Andrew any thoughts on the above?

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [July 30, 2019, 12:43pm UTC](https://discuss.elastic.co/t/cannot-start-service-winlogbeat-in-docker-windows-container/190092/7 "2019-07-30T12:43:50Z")

</div>

> [@HippyCraig](#):
>
> Just for curiosity sake services also get a PID is this not the case with containers?

PID 1 is all that matters when determining if a container will exit. So you need to keep the containers main process running in order to prevent the container from exiting and stopping any other processes that may be running in the container (like those started by a service manager).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 27, 2019, 12:43pm UTC](https://discuss.elastic.co/t/cannot-start-service-winlogbeat-in-docker-windows-container/190092/8 "2019-08-27T12:43:51Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
