# Collect everything from a host

**URL:** <https://discuss.elastic.co/t/collect-everything-from-a-host/326532>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [February 27, 2023, 1:16am UTC](https://discuss.elastic.co/t/collect-everything-from-a-host/326532 "2023-02-27T01:16:36Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![gunlomboy](https://avatars.discourse-cdn.com/v4/letter/g/c0e974/32.png) [@gunlomboy](https://discuss.elastic.co/u/gunlomboy)\
**Post date:** [February 27, 2023, 1:16am UTC](https://discuss.elastic.co/t/collect-everything-from-a-host/326532/1 "2023-02-27T01:16:36Z")

</div>

Hi,

It seems that there is no config which will allow winlogbeat to collect everything available on a given host.

event.log: \*

I want to deploy winlogbeat across my environment, but hosts have differing roles and therefore the available event logs and event channels differ from host to host.

I want a single configuration which I can deploy to all hosts, so this could be achieved by including absolutely all event logs/channels we know about in the environment in the config.

My question is: will winlogbeat thrash the CPU if it can't find a particular event log/channel on a host? Will it just constantly check to try to find the log?

Obviously, if that's the case, the solution won't work.

Thanks.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 27, 2023, 3:17am UTC](https://discuss.elastic.co/t/collect-everything-from-a-host/326532/2 "2023-03-27T03:17:28Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
