# Event Log Record Number Tracking

**URL:** <https://discuss.elastic.co/t/event-log-record-number-tracking/106245>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [November 2, 2017, 8:21pm UTC](https://discuss.elastic.co/t/event-log-record-number-tracking/106245 "2017-11-02T20:21:05Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![KRasekhi](https://avatars.discourse-cdn.com/v4/letter/k/85e7bf/32.png) [@KRasekhi](https://discuss.elastic.co/u/KRasekhi)\
**Post date:** [November 2, 2017, 8:21pm UTC](https://discuss.elastic.co/t/event-log-record-number-tracking/106245/1 "2017-11-02T20:21:05Z")

</div>

Hi,

For Winlogbeat there is a file in c:\ProgramData\Winlogbeat.winlogbeat.yml that shows you the last record sent to Elasticsearch from the machine. I noticed that if you delete this file it will not resend the events to ES and instead will recreate the file with the last record sent. I assume there is also record keeping in Elasticsearch but I can't find where it is located. If i delete the entire index and the .winlogbeat.yml the event log data will resend , but without deleting the index it will not resend.

Thanks!

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [November 2, 2017, 8:49pm UTC](https://discuss.elastic.co/t/event-log-record-number-tracking/106245/2 "2017-11-02T20:49:26Z")

</div>

> [@KRasekhi](#):
>
> I noticed that if you delete this file it will not resend the events to ES and instead will recreate the file with the last record sent.

Did you stop Winlogbeat before deleting the file? No state is stored in ES. That file holds all of the state that Winlogbeat will use to resume during a restart.

---

<div class="post-metadata">

**Author:** ![KRasekhi](https://avatars.discourse-cdn.com/v4/letter/k/85e7bf/32.png) [@KRasekhi](https://discuss.elastic.co/u/KRasekhi)\
**Post date:** [November 3, 2017, 12:09pm UTC](https://discuss.elastic.co/t/event-log-record-number-tracking/106245/3 "2017-11-03T12:09:17Z")

</div>

I did and double checked to make sure the service was in a stopped state before removing the file. When it started the file back up it was right back where it left off before deletion.

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [November 3, 2017, 12:22pm UTC](https://discuss.elastic.co/t/event-log-record-number-tracking/106245/4 "2017-11-03T12:22:01Z")

</div>

How are you determining where Winlogbeat is starting from?

Are you using `ignore_older`? Please share the config you are using.

---

<div class="post-metadata">

**Author:** ![KRasekhi](https://avatars.discourse-cdn.com/v4/letter/k/85e7bf/32.png) [@KRasekhi](https://discuss.elastic.co/u/KRasekhi)\
**Post date:** [November 3, 2017, 1:23pm UTC](https://discuss.elastic.co/t/event-log-record-number-tracking/106245/5 "2017-11-03T13:23:01Z")

</div>

I am pulling the entire security log filtering on event\_id: 4624

winlogbeat.event\_logs:

- name: Application  
ignore\_older: 72h
- name: Security  
event\_id: 4624
- name: System

After some more testing i noticed a few things -

- Stopped the Service -\> Deleted the .winlogbeat.yml -\> Started the Service
- The File was recreated at the same record count before being deleted but it is re-sending the Event logs to ES which led the confusion. On another machine the record count would reset when the file was deleted and increase as the logs were being sent to ES... Not sure why in this case it goes straight to the last record even though it hasn't been sent yet.

update\_time: 2017-11-03T13:21:21.6228552Z  
event\_logs:

- name: Application  
record\_number: 363121  
timestamp: 2017-11-03T13:20:53Z
- name: Security  
record\_number: 543894019  
timestamp: 2017-11-03T13:21:16.7638552Z
- name: System  
record\_number: 682637  
timestamp: 2017-11-03T13:20:53.2468552Z

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [November 3, 2017, 1:40pm UTC](https://discuss.elastic.co/t/event-log-record-number-tracking/106245/6 "2017-11-03T13:40:39Z")

</div>

It's going to be very hard to observe the starting state by looking at this file because it is updated so quickly after Winlogbeat is started. If you want to confirm the first record\_number then I recommend enabling the file output and looking at the first event that gets written.

1. Stop Winlogbeat
2. Enable the file output in your config.
3. Delete the registry file (aka .winlogbeat.yml).
4. Delete any previously created output files.
5. Start Winlogbeat.
6. Observe the record\_number of the first event written to the file output. (Note that these output files automatically rotate so the first record will be at the beginning of the oldest file.)

The record\_number in the registry file is updated after the event has been confirmed to have been received by the output. So when Elasticsearch responds with a 200 OK to Winlogbeat's \_bulk indexing request then Winlogbeat will eventually persist this number. This is how Winlogbeat achieves its at-least-once delivery semantics.

This is the config to use for the [file output](https://www.elastic.co/guide/en/beats/winlogbeat/current/configuration-winlogbeat-options.html).

```auto
output.file:
  path: 'C:/ProgramData/winlogbeat/output'
  filename: events.json
  number_of_files: 50

```

---

<div class="post-metadata">

**Author:** ![KRasekhi](https://avatars.discourse-cdn.com/v4/letter/k/85e7bf/32.png) [@KRasekhi](https://discuss.elastic.co/u/KRasekhi)\
**Post date:** [November 3, 2017, 2:30pm UTC](https://discuss.elastic.co/t/event-log-record-number-tracking/106245/7 "2017-11-03T14:30:48Z")

</div>

Thanks Andrew! Appreciate all the help.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 1, 2017, 2:30pm UTC](https://discuss.elastic.co/t/event-log-record-number-tracking/106245/8 "2017-12-01T14:30:56Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
