# Correct way to Start and Stop Winlogbeat with Powershell

**URL:** <https://discuss.elastic.co/t/correct-way-to-start-and-stop-winlogbeat-with-powershell/149428>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [September 21, 2018, 10:04am UTC](https://discuss.elastic.co/t/correct-way-to-start-and-stop-winlogbeat-with-powershell/149428 "2018-09-21T10:04:59Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![JKCode](https://avatars.discourse-cdn.com/v4/letter/j/b9e5f3/32.png) [@JKCode](https://discuss.elastic.co/u/JKCode)\
**Post date:** [September 21, 2018, 10:04am UTC](https://discuss.elastic.co/t/correct-way-to-start-and-stop-winlogbeat-with-powershell/149428/1 "2018-09-21T10:04:59Z")

</div>

Hi All,  
Newbie Alert!!  
I have been facing issues using Winlogbeats to ship localhost logs (application, system, security, etc.) to Elasticsearch.  
I have been following the instructions in the documentation, however, I am ONLY able to start the logs shipping to ES with the following command:

`PS> .\winlogbeat.exe -c .\winlogbeat.yml -e`

This displays DEBUG, INFO etc in the terminal window while operational and the only way for me to stop it is with Ctrl C. This is causing my logs to get corrupted and they cannot be viewed in Windows Event Viewer after Force Stopping Winlgbearts.

The Start-Service winlogbeat command does not initiate logs shipping to ES either.

Request please provide me with link to the correct procedures to Start and Stop the WInlogbeats Service on WInodws 10 using Powershell; or elaborate on the correct procedures here.

Any help is much appreciated!

Thanks in advance!

Regards,  
Juneid

---

<div class="post-metadata">

**Author:** ![JKCode](https://avatars.discourse-cdn.com/v4/letter/j/b9e5f3/32.png) [@JKCode](https://discuss.elastic.co/u/JKCode)\
**Post date:** [September 26, 2018, 7:49am UTC](https://discuss.elastic.co/t/correct-way-to-start-and-stop-winlogbeat-with-powershell/149428/2 "2018-09-26T07:49:03Z")

</div>

Hi All,

I am posting again just to check if this query is irrelevant as there has been no response.

I have been told that my Seniors in Development that Windows log corruption is occurring due to Winlogbeat remaining latched to the logs which render them not viewable in Event Viewer (as corrupted) and irretrievable. This is due to the abrupt shutdown command with Ctrl C.

Any info / guidance is appreciated.

Thanks and Regards

Juneid

---

<div class="post-metadata">

**Author:** ![dedemorton](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dedemorton/32/84409_2.png) [@dedemorton](https://discuss.elastic.co/u/dedemorton)\
**Post date:** [September 28, 2018, 6:23am UTC](https://discuss.elastic.co/t/correct-way-to-start-and-stop-winlogbeat-with-powershell/149428/3 "2018-09-28T06:23:25Z")

</div>

If you followed the steps in the [getting started docs](https://www.elastic.co/guide/en/beats/winlogbeat/current/winlogbeat-installation.html) to install the service, you should be able to start the service with `Start-Service winlogbeat` and stop it with `Stop-Service winlogbeat`.

I just pulled down and installed the latest version of the stack, installed the service, and started the service without issues. I'd suggest getting the default configuration working before you modify the configuration.

---

<div class="post-metadata">

**Author:** ![dedemorton](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dedemorton/32/84409_2.png) [@dedemorton](https://discuss.elastic.co/u/dedemorton)\
**Post date:** [September 28, 2018, 6:25am UTC](https://discuss.elastic.co/t/correct-way-to-start-and-stop-winlogbeat-with-powershell/149428/4 "2018-09-28T06:25:18Z")

</div>

Also see the [docs](https://www.elastic.co/guide/en/beats/winlogbeat/current/winlogbeat-starting.html) about starting and stopping the service.

---

<div class="post-metadata">

**Author:** ![JKCode](https://avatars.discourse-cdn.com/v4/letter/j/b9e5f3/32.png) [@JKCode](https://discuss.elastic.co/u/JKCode)\
**Post date:** [September 30, 2018, 7:14am UTC](https://discuss.elastic.co/t/correct-way-to-start-and-stop-winlogbeat-with-powershell/149428/5 "2018-09-30T07:14:31Z")

</div>

Thank you for the response @dedemorton. Shall attempt this again and update.

Regards,  
JK

---

<div class="post-metadata">

**Author:** ![JKCode](https://avatars.discourse-cdn.com/v4/letter/j/b9e5f3/32.png) [@JKCode](https://discuss.elastic.co/u/JKCode)\
**Post date:** [September 30, 2018, 8:17am UTC](https://discuss.elastic.co/t/correct-way-to-start-and-stop-winlogbeat-with-powershell/149428/6 "2018-09-30T08:17:13Z")

</div>

Hi All,

My mistake with this was, redirecting myself to links within the documentation which was the cause of my confusion.

I would recommend new users to stick to the process steps in the documentation to specifically setup, basic configuration and starting the beat, before exploring other links within the documentation.

I suppose Windows users should be running commands in the following order:

Setup:

1. Install  
`PS C:\Users\Administrator&gt; cd 'C:\Program Files\Winlogbeat' PS C:\Program Files\Winlogbeat&gt; .\install-service-winlogbeat.ps1`

2. Proceed to configure winlogbeat.yml file= basic  
a. Applications  
b. Output

3. Load Kibana Dashboards

4. Start Winlogbeat  
`PS C:\Program Files\Winlogbeat&gt; Start-Service winlogbeat`

5. Stop Winlogbeat  
`PS C:\Program Files\Winlogbeat&gt; Stop-Service winlogbeat`

Cheers!  
JK

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 28, 2018, 10:17am UTC](https://discuss.elastic.co/t/correct-way-to-start-and-stop-winlogbeat-with-powershell/149428/7 "2018-10-28T10:17:14Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
