# EventLog input/plugin only supports Application, System and Security.... why?!?!?

**URL:** <https://discuss.elastic.co/t/eventlog-input-plugin-only-supports-application-system-and-security-why/49105>\
**Category:** Logstash\
**Created:** [May 3, 2016, 8:51pm UTC](https://discuss.elastic.co/t/eventlog-input-plugin-only-supports-application-system-and-security-why/49105 "2016-05-03T20:51:40Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Luis\_Pereira](https://avatars.discourse-cdn.com/v4/letter/l/49beb7/32.png) [@Luis\_Pereira](https://discuss.elastic.co/u/Luis_Pereira)\
**Post date:** [May 3, 2016, 8:51pm UTC](https://discuss.elastic.co/t/eventlog-input-plugin-only-supports-application-system-and-security-why/49105/1 "2016-05-03T20:51:40Z")

</div>

Hi,

I've got a custom Windows Event log file, but when I specify this logfile name, logstash stash complains with the following error message... any knows why its restrictive to 3 known logfiles?

←[31mInvalid setting for eventlog input plugin:

input {  
eventlog {  
# This setting must be a ["Application", "Security", "System"]  
# Expected one of ["Application", "Security", "System"], got ["Application  
", "CustomLogfileName"]  
logfile =\> ["Application", "CustomLogfileName"]  
...  
}  
} {:level=\>:error}←[0m  
←[31mfetched an invalid config {:config=\>"input {\n eventlog {\n type =\> "  
Win32-EventLog"\n logfile =\> ["Application", "CustomLogfileName"]\n }\n}\n\nout  
put {\n stdout { codec =\> rubydebug }\n}\n\n\n", :reason=\>"Something is wrong  
with your configuration.", :level=\>:error}←[0m  
The signal HUP is in use by the JVM and will not work correctly on this platform

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [May 3, 2016, 11:02pm UTC](https://discuss.elastic.co/t/eventlog-input-plugin-only-supports-application-system-and-security-why/49105/2 "2016-05-03T23:02:58Z")

</div>

Why not use winlogbeat instead? [https://www.elastic.co/guide/en/beats/winlogbeat/current/index.html](https://www.elastic.co/guide/en/beats/winlogbeat/current/index.html)

---

<div class="post-metadata">

**Author:** ![Luis\_Pereira](https://avatars.discourse-cdn.com/v4/letter/l/49beb7/32.png) [@Luis\_Pereira](https://discuss.elastic.co/u/Luis_Pereira)\
**Post date:** [May 4, 2016, 9:05am UTC](https://discuss.elastic.co/t/eventlog-input-plugin-only-supports-application-system-and-security-why/49105/3 "2016-05-04T09:05:15Z")

</div>

Sure I don't mind... but I guess what I was trying to find out is why it doesn't allow other logfiles to be used as opposed to using winlogbeat. I've seen winlogbeat already, but was just wondering why logstash had that restrictions.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [May 4, 2016, 9:36am UTC](https://discuss.elastic.co/t/eventlog-input-plugin-only-supports-application-system-and-security-why/49105/4 "2016-05-04T09:36:27Z")

</div>

No idea sorry, PRs welcome though 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:59am UTC](https://discuss.elastic.co/t/eventlog-input-plugin-only-supports-application-system-and-security-why/49105/5 "2017-07-06T04:59:25Z")

</div>


