# Configuration of logstash for forwarding winlogbeats to a syslog server

**URL:** <https://discuss.elastic.co/t/configuration-of-logstash-for-forwarding-winlogbeats-to-a-syslog-server/252195>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [October 15, 2020, 12:54pm UTC](https://discuss.elastic.co/t/configuration-of-logstash-for-forwarding-winlogbeats-to-a-syslog-server/252195 "2020-10-15T12:54:36Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![jjoseph8008](https://avatars.discourse-cdn.com/v4/letter/j/848f3c/32.png) [@jjoseph8008](https://discuss.elastic.co/u/jjoseph8008)\
**Post date:** [October 15, 2020, 12:54pm UTC](https://discuss.elastic.co/t/configuration-of-logstash-for-forwarding-winlogbeats-to-a-syslog-server/252195/1 "2020-10-15T12:54:36Z")

</div>

I am using winlogbeats to send log files from a windows box to logstash. My logstash is collecting Linux syslogs over port 514,forwarding them to a local NGINX service that will then forward it to our SIEM syslog server (this piece works). I was wondering if anyone knows whether I can use the same port 514 to receive winlogbeats traffic. I think there is some additional configuration required in the logstash file for winlogbeats traffic, but I was not sure. Please advise.

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [October 15, 2020, 6:32pm UTC](https://discuss.elastic.co/t/configuration-of-logstash-for-forwarding-winlogbeats-to-a-syslog-server/252195/2 "2020-10-15T18:32:51Z")

</div>

You cannot send Winlogbeat events directly over syslog as it only supports Elasticsearch/Logstash/Kafka/Redis/File as outputs. You would need to configure the [beats input](https://www.elastic.co/guide/en/logstash/current/plugins-inputs-beats.html) in Logstash to receive the data from Winlogbeat. Then you can have Logstash forward the data to wherever you need it to go.

---

<div class="post-metadata">

**Author:** ![jjoseph8008](https://avatars.discourse-cdn.com/v4/letter/j/848f3c/32.png) [@jjoseph8008](https://discuss.elastic.co/u/jjoseph8008)\
**Post date:** [October 16, 2020, 2:54am UTC](https://discuss.elastic.co/t/configuration-of-logstash-for-forwarding-winlogbeats-to-a-syslog-server/252195/3 "2020-10-16T02:54:07Z")

</div>

thank you !

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 13, 2020, 4:54am UTC](https://discuss.elastic.co/t/configuration-of-logstash-for-forwarding-winlogbeats-to-a-syslog-server/252195/4 "2020-11-13T04:54:09Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
