# Changing winlogbeat from elasticsearch to logstash

**URL:** <https://discuss.elastic.co/t/changing-winlogbeat-from-elasticsearch-to-logstash/350865>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [January 11, 2024, 2:02pm UTC](https://discuss.elastic.co/t/changing-winlogbeat-from-elasticsearch-to-logstash/350865 "2024-01-11T14:02:48Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![MColeman](https://avatars.discourse-cdn.com/v4/letter/m/7feea3/32.png) [@MColeman](https://discuss.elastic.co/u/MColeman)\
**Post date:** [January 11, 2024, 2:02pm UTC](https://discuss.elastic.co/t/changing-winlogbeat-from-elasticsearch-to-logstash/350865/1 "2024-01-11T14:02:48Z")

</div>

Hi,  
I started off a cluster with winlogbeat going directly to elasticsearch and using the pre-built dashboards. All that worked well out of the box. Now I'd like to send my winlogbeat data through logstash so I can do some email alerting out of logstash on the winlogbeat data and continue to use the pre-built dashboards.  
I configured logstash to listen for the beats output with no issue, and I have a conditional elasticsearch output block to send the winlogbeat data into its own index like this:

```auto
input {
     beats {
           port => 5044
		   type => winlogbeat
        }
...
if [type] == "winlogbeat" {
	            elasticsearch {
	              hosts => ["https://localhost:9200"]	
				  index => "%{[@metadata][beat]}-%{[@metadata][version]}-%{+YYYY.MM.dd}"

```

and that works fine. The issue seems to be when I go to the pre-built dashboards I get a failed shards message for the new winlogbeat index.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/8/5/85aa22d1cda2c93aec9edc2db8fd809cfbbc457b.png)

I guess my question is how can I make the logstash winlogbeat input match the winlogbeat input that goes directly to elasticsearch so that these dashboards continue to work?

Thanks!  
Mark

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [January 11, 2024, 5:27pm UTC](https://discuss.elastic.co/t/changing-winlogbeat-from-elasticsearch-to-logstash/350865/2 "2024-01-11T17:27:52Z")

</div>

You need to configure the output as the example in the [documentation](https://www.elastic.co/guide/en/logstash/current/winlogbeat-modules.html#use-winlogbeat-ingest-pipelines) so it will also use the ingest pipeline in Elasticsearch.

---

<div class="post-metadata">

**Author:** ![MColeman](https://avatars.discourse-cdn.com/v4/letter/m/7feea3/32.png) [@MColeman](https://discuss.elastic.co/u/MColeman)\
**Post date:** [January 12, 2024, 10:33pm UTC](https://discuss.elastic.co/t/changing-winlogbeat-from-elasticsearch-to-logstash/350865/3 "2024-01-12T22:33:11Z")

</div>

Hi Leandro! That pointed me in the right direction, although it differed from the documentation. I did have to load the ingest pipelines using this command

```auto
winlogbeat setup --pipelines
not 
winlogbeat setup --pipelines --modules sysmon,security

```

but then the inserts from logstash to elasticsearch would fail so I had to add this filter in logstash to choose the correct pipeline

```auto
#filter for winlogbeat
 if [type] == "winlogbeat"{
    mutate { add_field => { "[@metadata][pipeline]" => "winlogbeat-%{[agent][version]}-routing" } }
  } else if !([@metadata][pipeline]) {
    mutate { add_field => { "[@metadata][pipeline]" => "" } }
  }  
#end filter for winlogbeat

```

Now the dashboards are working and logstash is receiving the data like it should.

Thanks!  
Mark

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 10, 2024, 12:33am UTC](https://discuss.elastic.co/t/changing-winlogbeat-from-elasticsearch-to-logstash/350865/4 "2024-02-10T00:33:50Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
