# ELMAH, xml and winlogbeat

**URL:** <https://discuss.elastic.co/t/elmah-xml-and-winlogbeat/246473>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [August 26, 2020, 2:43pm UTC](https://discuss.elastic.co/t/elmah-xml-and-winlogbeat/246473 "2020-08-26T14:43:33Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![kawalec](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kawalec/32/46404_2.png) [@kawalec](https://discuss.elastic.co/u/kawalec)\
**Post date:** [August 26, 2020, 2:43pm UTC](https://discuss.elastic.co/t/elmah-xml-and-winlogbeat/246473/1 "2020-08-26T14:43:33Z")

</div>

We are using ELMAH for logging and it writes an xml file for every error. Is there a way to use Winlogbeat to get these files into kibana?

Thanks

---

<div class="post-metadata">

**Author:** ![jsoriano](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsoriano/32/27920_2.png) [@jsoriano](https://discuss.elastic.co/u/jsoriano)\
**Post date:** [August 26, 2020, 7:17pm UTC](https://discuss.elastic.co/t/elmah-xml-and-winlogbeat/246473/2 "2020-08-26T19:17:46Z")

</div>

Hey @kawalec,

Have you tried to collect these log files with Filebeat?

---

<div class="post-metadata">

**Author:** ![kawalec](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kawalec/32/46404_2.png) [@kawalec](https://discuss.elastic.co/u/kawalec)\
**Post date:** [August 27, 2020, 1:20pm UTC](https://discuss.elastic.co/t/elmah-xml-and-winlogbeat/246473/3 "2020-08-27T13:20:28Z")

</div>

No I did not. We are just starting our ELK journey. I wrongly assumed that you only used winlogbeat on windows and filebeat for linux.

So Filebeat will be able to parse xml files fight into kibana?

---

<div class="post-metadata">

**Author:** ![jsoriano](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsoriano/32/27920_2.png) [@jsoriano](https://discuss.elastic.co/u/jsoriano)\
**Post date:** [August 27, 2020, 3:02pm UTC](https://discuss.elastic.co/t/elmah-xml-and-winlogbeat/246473/4 "2020-08-27T15:02:24Z")

</div>

Welcome to this journey then 🙂

Winlogbeat is specialized on collecting logs from the Windows Event Log, but it cannot collect logs from files.  
Filebeat can collect logs from files on any operating system, but it also has [many other inputs](https://www.elastic.co/guide/en/beats/filebeat/7.9/configuration-filebeat-options.html).

Both Filebeat and Winlogbeat can do some parsing locally using [processors](https://www.elastic.co/guide/en/beats/filebeat/7.9/filtering-and-enhancing-data.html). Also, you can use [ingest pipelines](https://www.elastic.co/guide/en/elasticsearch/reference/7.9/ingest.html) in Elasticsearch to do the processing there just before ingesting.  
Filebeat also includes a set of [modules](https://www.elastic.co/guide/en/beats/filebeat/7.9/filebeat-modules.html), that include predefined configurations for many services.

Once the logs are collected and parsed, they can be visualized in Kibana.

For XML there is no parser in Beats or in Elasticsearch, but you could use Logstash for that, it has an [XML plugin](https://www.elastic.co/guide/en/logstash/7.9/plugins-filters-xml.html). You could use Beats for collection and Logstash for parsing.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 24, 2020, 5:02pm UTC](https://discuss.elastic.co/t/elmah-xml-and-winlogbeat/246473/5 "2020-09-24T17:02:31Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
