# Collecting logs from windows server

**URL:** <https://discuss.elastic.co/t/collecting-logs-from-windows-server/113136>\
**Category:** Beats\
**Created:** [December 25, 2017, 8:54am UTC](https://discuss.elastic.co/t/collecting-logs-from-windows-server/113136 "2017-12-25T08:54:03Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![YuWatanabe](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yuwatanabe/32/13259_2.png) [@YuWatanabe](https://discuss.elastic.co/u/YuWatanabe)\
**Post date:** [December 25, 2017, 8:54am UTC](https://discuss.elastic.co/t/collecting-logs-from-windows-server/113136/1 "2017-12-25T08:54:03Z")

</div>

Hi!

I would like to get advice for gathering text logs on windows server.  
I have a log stream that is implemented as below. Important part of below stream is that all logs must be also collected on node2 as a log file(\*) . This log file will be used in an emergency case.

[] represents a single node.

node1-----------node2---------------------------------------------node3-------------node4  
[devices] ---\> [RSyslog ---\> file(\*) \<--- filebeat1] ---\> [logstash] ---\> [elasticsearch]

I am now planning to collect text logs from _windows server_ using filebeat. So I want to add 2nd stream as below .

[devices] ---\> [RSyslog ---\> file(\*) \<--- filebeat1] ---\> [logstash] ---\> [elasticsearch]  
[filebeat2] --\> xxx

_However_, problem is I cannot send log from **filebeat** to **Rsyslog** since filebeat does not support _syslog_ output. Ideally , I do not want to change orders of the data stream which will make things complicated. LIke, send event from **filebeat2** to **logstash**.

Are there any good idea which I can send log from **filebeat2** to **node2**?

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [December 26, 2017, 7:07am UTC](https://discuss.elastic.co/t/collecting-logs-from-windows-server/113136/2 "2017-12-26T07:07:03Z")

</div>

I am not sure I follow your reasoning around why Filebeat on **server1** and **server2** can not send data directly to Logstash? Can you please elaborate on why you need to include Redis at all? If you need Redis, why can Logstash not pull directly from it?

---

<div class="post-metadata">

**Author:** ![YuWatanabe](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yuwatanabe/32/13259_2.png) [@YuWatanabe](https://discuss.elastic.co/u/YuWatanabe)\
**Post date:** [December 26, 2017, 9:04am UTC](https://discuss.elastic.co/t/collecting-logs-from-windows-server/113136/3 "2017-12-26T09:04:46Z")

</div>

@Christian_Dahlqvist

My explanation was ambiguous sorry about that. I have amended my explanation . Would you please take a look at it?

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [December 26, 2017, 9:08am UTC](https://discuss.elastic.co/t/collecting-logs-from-windows-server/113136/4 "2017-12-26T09:08:18Z")

</div>

Why not just send data from the filebeat2 instance directly to Logstash?

---

<div class="post-metadata">

**Author:** ![YuWatanabe](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yuwatanabe/32/13259_2.png) [@YuWatanabe](https://discuss.elastic.co/u/YuWatanabe)\
**Post date:** [December 26, 2017, 9:09am UTC](https://discuss.elastic.co/t/collecting-logs-from-windows-server/113136/5 "2017-12-26T09:09:31Z")

</div>

Because events will bypass node2 . _Log file_ will not be created in node2.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 15, 2018, 8:54am UTC](https://discuss.elastic.co/t/collecting-logs-from-windows-server/113136/6 "2018-01-15T08:54:24Z")

</div>

This topic was automatically closed after 21 days. New replies are no longer allowed.
