# Collecting log files in addition to Windows event logs

**URL:** <https://discuss.elastic.co/t/collecting-log-files-in-addition-to-windows-event-logs/59998>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [September 7, 2016, 3:04pm UTC](https://discuss.elastic.co/t/collecting-log-files-in-addition-to-windows-event-logs/59998 "2016-09-07T15:04:00Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Diggy](https://avatars.discourse-cdn.com/v4/letter/d/e99b99/32.png) [@Diggy](https://discuss.elastic.co/u/Diggy)\
**Post date:** [September 7, 2016, 3:04pm UTC](https://discuss.elastic.co/t/collecting-log-files-in-addition-to-windows-event-logs/59998/1 "2016-09-07T15:04:00Z")

</div>

Hi, all.

I'm tasked with trying to get certain application logs captured by ELK. I have Winlogbeat working on a test server, and it's forwarding Event Logs. Is there a way (as with Filebeat) to capture logs from, say, SQL Server, or some other application. We have a particular program that creates e.g. log1534.txt today, log1535.txt tomorrow, and log 1536.txt the following day. Note that, on occasion, two or more log files will be created during the same day. Can I forward those to ELK? Can I use Winlogbeat?

Thanks.

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [September 7, 2016, 7:50pm UTC](https://discuss.elastic.co/t/collecting-log-files-in-addition-to-windows-event-logs/59998/2 "2016-09-07T19:50:53Z")

</div>

You can forward your log files using Filebeat. So you will have both Winlogbeat and Filebeat installed on your Windows server.

With Filebeat you can use a wildcard pattern or regex to match those filenames.

---

<div class="post-metadata">

**Author:** ![Diggy](https://avatars.discourse-cdn.com/v4/letter/d/e99b99/32.png) [@Diggy](https://discuss.elastic.co/u/Diggy)\
**Post date:** [September 7, 2016, 8:16pm UTC](https://discuss.elastic.co/t/collecting-log-files-in-addition-to-windows-event-logs/59998/3 "2016-09-07T20:16:07Z")

</div>

Thanks, Andrew. My bad for not having seen that Filebeat can be installed on Windows. I hate it when I do stuff like that. I'll give it a go, and post to the Filebeat forum if I have any further questions.

Again, thanks!

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [September 10, 2016, 8:16pm UTC](https://discuss.elastic.co/t/collecting-log-files-in-addition-to-windows-event-logs/59998/4 "2016-09-10T20:16:17Z")

</div>

This topic was automatically closed 3 days after the last reply. New replies are no longer allowed.
