# ELK on Windows Server 2016 with Filebeat on Windows 10 client - problems

**URL:** <https://discuss.elastic.co/t/elk-on-windows-server-2016-with-filebeat-on-windows-10-client-problems/209667>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [November 27, 2019, 11:02am UTC](https://discuss.elastic.co/t/elk-on-windows-server-2016-with-filebeat-on-windows-10-client-problems/209667 "2019-11-27T11:02:01Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![JY\_DT](https://avatars.discourse-cdn.com/v4/letter/j/5e9695/32.png) [@JY\_DT](https://discuss.elastic.co/u/JY_DT)\
**Post date:** [November 27, 2019, 11:02am UTC](https://discuss.elastic.co/t/elk-on-windows-server-2016-with-filebeat-on-windows-10-client-problems/209667/1 "2019-11-27T11:02:02Z")

</div>

Hello,

I've setup ELK 7.4.2 on Windows Server 2016, with some of these references:

> **[Demystifying ELK stack](https://cezarypiatek.github.io/post/demystifying-elk-stack/)**
>
> How to easily implement centralized logging system based on ELK stack.

  
[http://robwillis.info/2019/05/installing-elk-7-elasticsearch-logstash-and-kibana-windows-server-2016/](http://robwillis.info/2019/05/installing-elk-7-elasticsearch-logstash-and-kibana-windows-server-2016/)  

> **[Installing the ELK Stack on Windows | Logz.io](https://logz.io/blog/installing-the-elk-stack-on-windows/)**
>
> This tutorial provides a step-by-step guide to installing the ELK Stack (Elasticsearch, Logstash and Kibana) as services on Windows Server 2012.

and I've setup Filebeat on my Windows 10 client machine.  
It looks like all the installations are fine, and I'm able to start all services.  
But no data seems to be inserted into Elasticsearch. I'm not sure what's going wrong.

On the server machine:

1. When I enter this in a browser:  
[http://localhost:9200/](http://localhost:9200/)

I see the details correctly.

1. And on this:  
[http://localhost:9200/\_cat/indices](http://localhost:9200/_cat/indices)

I see these indexes:  
green open .kibana\_task\_manager\_1 MNLTzyjNQk2\_DBwLbLAUjQ 1 0 2 0 13.3kb 13.3kb  
green open kibana\_sample\_data\_ecommerce MD4yCUShR4KJi0qzrWo1lQ 1 0 4675 0 4.4mb 4.4mb  
green open .apm-agent-configuration bqpM6GzVS7mJJNtxbWrVvg 1 0 0 0 283b 283b  
green open .kibana\_1 9S6hqlJnS2KxsKPYh1viyw 1 0 74 7 954.3kb 954.3kb

1. On viewing Kibana, in the browser:  
[http://127.0.0.1:5601/](http://127.0.0.1:5601/) and then selecting "Index Patterns", I see only

kibana\_sample\_data\_ecommerce

and I don't see anything related to filebeat\*

On the Client machine:

1. Filebeat is installed and configured correctly.  
I've enabled logstash output with the correct IP and port address.

What could be wrong? I should be able to see the indices getting created and then be able to query for data.

Thanks,  
Jy

---

<div class="post-metadata">

**Author:** ![kvch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kvch/32/72058_2.png) [@kvch](https://discuss.elastic.co/u/kvch)\
**Post date:** [November 27, 2019, 12:58pm UTC](https://discuss.elastic.co/t/elk-on-windows-server-2016-with-filebeat-on-windows-10-client-problems/209667/2 "2019-11-27T12:58:26Z")

</div>

Could you please share you configuration formatted using `</>` and the debug logs of Filebeat?

---

<div class="post-metadata">

**Author:** ![JY\_DT](https://avatars.discourse-cdn.com/v4/letter/j/5e9695/32.png) [@JY\_DT](https://discuss.elastic.co/u/JY_DT)\
**Post date:** [November 27, 2019, 1:25pm UTC](https://discuss.elastic.co/t/elk-on-windows-server-2016-with-filebeat-on-windows-10-client-problems/209667/3 "2019-11-27T13:25:50Z")

</div>

Yes, actually I have another discussion thread in the "Elasticsearch" forum on the same topic. I've posted the configurations there. Please check:

> [@ELK on Windows Server 2016 with Filebeat on Windows 10 client - not working](https://discuss.elastic.co/t/elk-on-windows-server-2016-with-filebeat-on-windows-10-client-not-working/209659/7):
>
> ''' 2019-11-26T18:40:43.330+0530 INFO instance/beat.go:607 Home path: [C:\Program Files\Filebeat] Config path: [C:\Program Files\Filebeat] Data path: [C:\Program Files\Filebeat\data] Logs path: [C:\Program Files\Filebeat\logs] 2019-11-26T18:40:43.335+0530 INFO instance/beat.go:615 Beat ID: 6487577c-a9c3-4918-8bdb-520ff8aa9a53 '''

---

<div class="post-metadata">

**Author:** ![JY\_DT](https://avatars.discourse-cdn.com/v4/letter/j/5e9695/32.png) [@JY\_DT](https://discuss.elastic.co/u/JY_DT)\
**Post date:** [November 27, 2019, 1:27pm UTC](https://discuss.elastic.co/t/elk-on-windows-server-2016-with-filebeat-on-windows-10-client-problems/209667/4 "2019-11-27T13:27:31Z")

</div>

Anyway, here again:

1. Filebeat:

\<  
filebeat.inputs:

- type: log  
enabled: true  
paths:

- C:\ProgramData\DiagramOne\STool\Trace\*

output.logstash:  
hosts: ["MyserverIP:5044"]  
bulk\_max\_size: 1024

/\>

These are the only things I've changed.

---

<div class="post-metadata">

**Author:** ![JY\_DT](https://avatars.discourse-cdn.com/v4/letter/j/5e9695/32.png) [@JY\_DT](https://discuss.elastic.co/u/JY_DT)\
**Post date:** [November 27, 2019, 1:28pm UTC](https://discuss.elastic.co/t/elk-on-windows-server-2016-with-filebeat-on-windows-10-client-problems/209667/5 "2019-11-27T13:28:23Z")

</div>

And for Logstash on the Server:  
The logstash.conf file contains:  
\<  
input {  
beats {  
port =\> 5044  
type =\> "log"  
}  
}

output {  
elasticsearch {  
hosts =\> "[http://localhost:9200](http://localhost:9200/)"  
sniffing =\> true  
manage\_template =\> false  
index =\> "%{[@metadata][beat]}-%{+YYYY.MM.dd}"  
document\_type =\> "%{[@metadata][type]}"  
}  
}  
/\>

---

<div class="post-metadata">

**Author:** ![JY\_DT](https://avatars.discourse-cdn.com/v4/letter/j/5e9695/32.png) [@JY\_DT](https://discuss.elastic.co/u/JY_DT)\
**Post date:** [November 27, 2019, 1:29pm UTC](https://discuss.elastic.co/t/elk-on-windows-server-2016-with-filebeat-on-windows-10-client-problems/209667/6 "2019-11-27T13:29:21Z")

</div>

And maybe loading the templates manually is required? I'm still checking this:

[https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-template.html](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-template.html)

---

<div class="post-metadata">

**Author:** ![JY\_DT](https://avatars.discourse-cdn.com/v4/letter/j/5e9695/32.png) [@JY\_DT](https://discuss.elastic.co/u/JY_DT)\
**Post date:** [November 28, 2019, 10:33am UTC](https://discuss.elastic.co/t/elk-on-windows-server-2016-with-filebeat-on-windows-10-client-problems/209667/7 "2019-11-28T10:33:09Z")

</div>

Hi,

I'm actually trying this now:  
Load the index template in Elasticsearch:  
[https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-template.html](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-template.html)  
and I get these errors in the log file.

'''  
2019-11-28T15:44:23.248+0530 INFO [publisher] pipeline/module.go:97 Beat name: Something  
2019-11-28T15:44:23.250+0530 INFO elasticsearch/client.go:170 Elasticsearch url: [http://192.168.103.84:9200](http://192.168.103.84:9200/)  
2019-11-28T15:44:25.269+0530 ERROR elasticsearch/elasticsearch.go:260 Error connecting to Elasticsearch at [http://192.168.103.84:9200](http://192.168.103.84:9200/): Get [http://192.168.103.84:9200](http://192.168.103.84:9200/): dial tcp 192.168.103.84:9200: connectex: No connection could be made because the target machine actively refused it.  
2019-11-28T15:44:25.269+0530 ERROR instance/beat.go:878 Exiting: Couldn't connect to any of the configured Elasticsearch hosts. Errors: [Error connection to Elasticsearch [http://192.168.103.84:9200](http://192.168.103.84:9200/): Get [http://192.168.103.84:9200](http://192.168.103.84:9200/): dial tcp 192.168.103.84:9200: connectex: No connection could be made because the target machine actively refused it.]  
'''

Please note that on the m/c where ELK is installed has the firewall disabled, and I've also added firewall rules to allow incoming to ELK. So, I'm not sure why this error occurs.

Also, I'm able to ping the ELK m/c from my client m/c.  
Thanks.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 26, 2019, 10:33am UTC](https://discuss.elastic.co/t/elk-on-windows-server-2016-with-filebeat-on-windows-10-client-problems/209667/8 "2019-12-26T10:33:09Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
