# Filebeat agent to get Operating System Logs

**URL:** <https://discuss.elastic.co/t/filebeat-agent-to-get-operating-system-logs/274101>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [May 26, 2021, 5:25pm UTC](https://discuss.elastic.co/t/filebeat-agent-to-get-operating-system-logs/274101 "2021-05-26T17:25:01Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![AJ18](https://avatars.discourse-cdn.com/v4/letter/a/f6c823/32.png) [@AJ18](https://discuss.elastic.co/u/AJ18)\
**Post date:** [May 26, 2021, 5:25pm UTC](https://discuss.elastic.co/t/filebeat-agent-to-get-operating-system-logs/274101/1 "2021-05-26T17:25:01Z")

</div>

Hi Team,

I am using Filebeat agent to get logs from an S3 bucket in my AWS Account and push them into Elasticsearch for visualisation.

I wish to also collect some logs from EC2 instances of OS Linux or Windows (syslogs and win events )  
Can filebeat agent be used to achieve this? Or do we require some different agent?

Also, is there a way to push this output from the Beats agent to an S3 bucket along with sending to Elasticsearch stack?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [May 26, 2021, 9:56pm UTC](https://discuss.elastic.co/t/filebeat-agent-to-get-operating-system-logs/274101/2 "2021-05-26T21:56:06Z")

</div>

The system module is designed exactly for this 🙂

---

<div class="post-metadata">

**Author:** ![AJ18](https://avatars.discourse-cdn.com/v4/letter/a/f6c823/32.png) [@AJ18](https://discuss.elastic.co/u/AJ18)\
**Post date:** [May 27, 2021, 4:37am UTC](https://discuss.elastic.co/t/filebeat-agent-to-get-operating-system-logs/274101/3 "2021-05-27T04:37:23Z")

</div>

Thanks for the prompt reply Mark.

I see that the System module does not support windows logs, will I have to install Winlogbeat agent?

Also, can these logs be sent to an S3 bucket after retrieval?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [May 27, 2021, 4:46am UTC](https://discuss.elastic.co/t/filebeat-agent-to-get-operating-system-logs/274101/4 "2021-05-27T04:46:04Z")

</div>

If by Windows logs you mean things in event viewer, yes you need Winlogbeat.

Neither Filebeat and Winlogbeat support output to s3, you would need to use something like Logstash to do that.

---

<div class="post-metadata">

**Author:** ![AJ18](https://avatars.discourse-cdn.com/v4/letter/a/f6c823/32.png) [@AJ18](https://discuss.elastic.co/u/AJ18)\
**Post date:** [May 28, 2021, 8:25am UTC](https://discuss.elastic.co/t/filebeat-agent-to-get-operating-system-logs/274101/5 "2021-05-28T08:25:24Z")

</div>

Thanks Mark. This helps.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 25, 2021, 10:25am UTC](https://discuss.elastic.co/t/filebeat-agent-to-get-operating-system-logs/274101/6 "2021-06-25T10:25:34Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
