# Elastic Agent Issues Sending Logs - How much longer we need to wait?

**URL:** <https://discuss.elastic.co/t/elastic-agent-issues-sending-logs-how-much-longer-we-need-to-wait/284145>\
**Category:** Beats\
**Tags:** elastic-agent\
**Created:** [September 14, 2021, 6:15am UTC](https://discuss.elastic.co/t/elastic-agent-issues-sending-logs-how-much-longer-we-need-to-wait/284145 "2021-09-14T06:15:46Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![ikbal](https://avatars.discourse-cdn.com/v4/letter/i/ee59a6/32.png) [@ikbal](https://discuss.elastic.co/u/ikbal)\
**Post date:** [September 14, 2021, 6:15am UTC](https://discuss.elastic.co/t/elastic-agent-issues-sending-logs-how-much-longer-we-need-to-wait/284145/1 "2021-09-14T06:15:47Z")

</div>

Hello Elastic,

I believe you know that this issues has been circulated in the wild and it seems that the issues still exist whereby the agent installed is not transporting windows event logs etc to the Elastic. The one can be received is metricbeat and the prevention of ransomware, malware or the logs not even sent to the Elasticsearch.

This is quite disappointing. Been think to bring this forward to the potential client in coming weeks. Can you guys please expedite this issues soonest possible?

Get your backend team to do some research and study more about Velocidex / Velociraptor team URL [https://www.velocidex.com/](https://www.velocidex.com/) and they seems more skillful doing stuff related to tls/ssl for https connection to the server and able to retrieve windows logs via https for forensics and remediation.

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [September 15, 2021, 12:54pm UTC](https://discuss.elastic.co/t/elastic-agent-issues-sending-logs-how-much-longer-we-need-to-wait/284145/2 "2021-09-15T12:54:39Z")

</div>

Elastic Agent can collect Windows event logs. You need to have a policy applied to the Agent that collects the logs. These are the Fleet integrations related to Windows event logs:

- `system` integration - Reads from Application, Security, and System event logs and maps data to Elastic Common Schema (ECS)
- `windows` integration - Reads from Sysmon, PowerShell, and ForwardedEvents and maps data to ECS.
- `winlog` integration - Custom `winlog` input to read from any Windows event channel.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 13, 2021, 12:55pm UTC](https://discuss.elastic.co/t/elastic-agent-issues-sending-logs-how-much-longer-we-need-to-wait/284145/3 "2021-10-13T12:55:36Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
