# Configure Winlogbeat to use Logstash and setup kibana dashboards at once

**URL:** <https://discuss.elastic.co/t/configure-winlogbeat-to-use-logstash-and-setup-kibana-dashboards-at-once/366357>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [September 10, 2024, 8:03pm UTC](https://discuss.elastic.co/t/configure-winlogbeat-to-use-logstash-and-setup-kibana-dashboards-at-once/366357 "2024-09-10T20:03:40Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![akabigsmokee](https://avatars.discourse-cdn.com/v4/letter/a/cab0a1/32.png) [@akabigsmokee](https://discuss.elastic.co/u/akabigsmokee)\
**Post date:** [September 10, 2024, 8:03pm UTC](https://discuss.elastic.co/t/configure-winlogbeat-to-use-logstash-and-setup-kibana-dashboards-at-once/366357/1 "2024-09-10T20:03:40Z")

</div>

Hello everyone,

Can you help me with an issue I'm facing? Is it possible to configure Winlogbeat to send output to Logstash while still loading the patterns and dashboards for Kibana? Below is a screenshot showing the error I'm encountering when setting up Winlogbeat.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ae50da04a035ebf6786c584472162467e0a4558.png)

---

<div class="post-metadata">

**Author:** ![akabigsmokee](https://avatars.discourse-cdn.com/v4/letter/a/cab0a1/32.png) [@akabigsmokee](https://discuss.elastic.co/u/akabigsmokee)\
**Post date:** [September 10, 2024, 8:09pm UTC](https://discuss.elastic.co/t/configure-winlogbeat-to-use-logstash-and-setup-kibana-dashboards-at-once/366357/2 "2024-09-10T20:09:33Z")

</div>

Here you find some snippets from the winlogbeat.yml

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1adb04cda019fd526c66ec0d70f09982cfa19122.png)

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [September 10, 2024, 8:28pm UTC](https://discuss.elastic.co/t/configure-winlogbeat-to-use-logstash-and-setup-kibana-dashboards-at-once/366357/3 "2024-09-10T20:28:00Z")

</div>

Hi @akabigsmokee Welcome to the community.

Please don't post pictures of text, they are hard to read and can't be searched used etc..

First configure winlogbeat to connect to Kibana as nd elasticsearch as output. Comment out logstash output.

Then run

`.\winlogbeat.exe setup -e`

Then comment out elasticsearch output and uncomment logstash output and start winlogbeat

That should do it.

---

<div class="post-metadata">

**Author:** ![akabigsmokee](https://avatars.discourse-cdn.com/v4/letter/a/cab0a1/32.png) [@akabigsmokee](https://discuss.elastic.co/u/akabigsmokee)\
**Post date:** [September 10, 2024, 8:52pm UTC](https://discuss.elastic.co/t/configure-winlogbeat-to-use-logstash-and-setup-kibana-dashboards-at-once/366357/4 "2024-09-10T20:52:03Z")

</div>

Thanks for the answer @stephenb !

I tried the solution you suggested I just have this issue I want the dashboards to use a specific index I used the following config on my winlogbeat.yml but the dashboards loaded on kibana still using the winlogbeat-\* index

lines added in the file :

```auto
setup.template.settings:
  index.number_of_shards: 1
  #index.codec: best_compression
  #_source.enabled: false
setup.template.name: "soc-data"
setup.template.pattern: "soc-data*"

# ---------------------------- Elasticsearch Output ----------------------------
output.elasticsearch:
  # Array of hosts to connect to.
  hosts: ["192.168.194.54:9200"]

  # Protocol - either http (default) or https.
  protocol: "https"

  # Authentication credentials - either API key or username/password.
  #api_key: "id:api_key"
  username: "elastic"
  password: " **************"
  index: 'soc-data-%{+xxxx.ww}'

output.elasticsearch.ssl.certificate_authorities: ["C:\\Program Files\\winlogbeat\\elasticsearch-ca.pem"]

```

When I load the dashboards they're still using the winlogbeat-\* index

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/5/6/56538e68fe79c87fe30ffdc25fe48581001579c8.png)

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [September 10, 2024, 10:52pm UTC](https://discuss.elastic.co/t/configure-winlogbeat-to-use-logstash-and-setup-kibana-dashboards-at-once/366357/5 "2024-09-10T22:52:40Z")

</div>

> [@akabigsmokee](#):
>
> I tried the solution you suggested I just have this issue I want the dashboards to use a specific index I used the following config on my winlogbeat.yml but the dashboards loaded on kibana still using the winlogbeat-\* index

That was not clear... what version?

Yes you can do that...

take a look at this...

> **[Configure Kibana dashboard loading | Winlogbeat Reference \[8.15\] | Elastic](https://www.elastic.co/guide/en/beats/winlogbeat/current/configuration-dashboards.html)**

```auto
setup.dashboards.enabled: true
setup.dashboards.index: "soc-data-*"

```

After you do that once you should disable as it will try to load the dashboards every time you start...

---

<div class="post-metadata">

**Author:** ![akabigsmokee](https://avatars.discourse-cdn.com/v4/letter/a/cab0a1/32.png) [@akabigsmokee](https://discuss.elastic.co/u/akabigsmokee)\
**Post date:** [September 11, 2024, 9:22am UTC](https://discuss.elastic.co/t/configure-winlogbeat-to-use-logstash-and-setup-kibana-dashboards-at-once/366357/6 "2024-09-11T09:22:47Z")

</div>

Hi @stephenb,  
I really appreciate your support,  
It solved my issue and i was able to make all the logs going through logstash and generate the dashboards with the custom made index.

---

<div class="post-metadata">

**Author:** ![akabigsmokee](https://avatars.discourse-cdn.com/v4/letter/a/cab0a1/32.png) [@akabigsmokee](https://discuss.elastic.co/u/akabigsmokee)\
**Post date:** [September 11, 2024, 9:24pm UTC](https://discuss.elastic.co/t/configure-winlogbeat-to-use-logstash-and-setup-kibana-dashboards-at-once/366357/7 "2024-09-11T21:24:16Z")

</div>

Hello again,

I just faced this problem that is related to the steps @stephenb advised me to follow. After I loaded the pattern aswell as the dashboards with the custom index I wanted then disable the settings for elasticsearch output and switch to logstash output. The documents come with double fields "field" and "field.keyword" and I got this error when I wanted to change the index for the rules. I added the Index in the rule settings and I got this error

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/1/8/18f53d3b4d12d754e794d4d903e77840aefd3f70.png)

Here is the error

```auto
EQL Validation Errors
verification_exception: Found 5 problems line 1:1: Unknown column [event.category], did you mean any of [rule.category, client.nat.port, event_id.keyword, vulnerability.category]? line 1:15: Unknown column [event.type], did you mean any of [event_type, dns.type, error.type, host.type, input.type, service.type, fields.type, endpoint_type, observer.type, elf.segments.type, client.bytes, event_id, event_type.keyword, file.type, observer.os.type, os.type, user_agent.os.type]? line 2:3: Cannot use field [process.name] due to ambiguities being mapped as [2] incompatible types: [text] in [soc-data-2024.09.10, soc-data-2024.09.11], [keyword] in [winlogbeat-7.17.23-2024.09.05-000001] line 2:33: Cannot use field [process.pe.original_file_name] due to ambiguities being mapped as [2] incompatible types: [text] in [soc-data-2024.09.11], [keyword] in [winlogbeat-7.17.23-2024.09.05-000001] line 3:2: Cannot use field [process.args] due to ambiguities being mapped as [2] incompatible types: [text] in [soc-data-2024.09.10, soc-data-2024.09.11], [keyword] in [winlogbeat-7.17.23-2024.09.05-000001]

```
