# FileBeat in Windows and LogStash in Linux

**URL:** <https://discuss.elastic.co/t/filebeat-in-windows-and-logstash-in-linux/73529>\
**Category:** Logstash\
**Created:** [February 1, 2017, 2:33pm UTC](https://discuss.elastic.co/t/filebeat-in-windows-and-logstash-in-linux/73529 "2017-02-01T14:33:22Z")\
**Posts on this page:** 13\
**Page:** 1

<div class="post-metadata">

**Author:** ![Shmuel.Bouhnik](https://avatars.discourse-cdn.com/v4/letter/s/ed8c4c/32.png) [@Shmuel.Bouhnik](https://discuss.elastic.co/u/Shmuel.Bouhnik)\
**Post date:** [February 1, 2017, 2:33pm UTC](https://discuss.elastic.co/t/filebeat-in-windows-and-logstash-in-linux/73529/1 "2017-02-01T14:33:22Z")

</div>

Hi,

I running FileBeat on Windows and LogStash on Linux.

When I'm sending a log file from FileBeat to LogStash ... LogStash is getting in utf8 and the grok filtering is not working. But when I'm sending the file from the linux system using the nc command, Logstash is getting in ASCII and everything is working well.

Does it a known issue?

Regards,

Shmuel  
PS: if logs is needed I can provide.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [February 1, 2017, 2:39pm UTC](https://discuss.elastic.co/t/filebeat-in-windows-and-logstash-in-linux/73529/2 "2017-02-01T14:39:43Z")

</div>

I'm not sure what you mean here. Does your log file contain any bytes with the eight bit set, i.e. an ASCII value \>127? If yes then it's not ASCII. If no then there's no difference between the ASCII representation of the text and the UTF-8 representation of the same text.

---

<div class="post-metadata">

**Author:** ![Shmuel.Bouhnik](https://avatars.discourse-cdn.com/v4/letter/s/ed8c4c/32.png) [@Shmuel.Bouhnik](https://discuss.elastic.co/u/Shmuel.Bouhnik)\
**Post date:** [February 1, 2017, 2:50pm UTC](https://discuss.elastic.co/t/filebeat-in-windows-and-logstash-in-linux/73529/3 "2017-02-01T14:50:24Z")

</div>

No ... where can I send I you the log ... they are little bit too big to put them here.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [February 1, 2017, 2:54pm UTC](https://discuss.elastic.co/t/filebeat-in-windows-and-logstash-in-linux/73529/4 "2017-02-01T14:54:44Z")

</div>

We don't need the whole log. A single line that exhibits the problem you describe will do. Make sure you format it as preformatted text when posting. The same line fed through `hexdump -C` could also be useful.

---

<div class="post-metadata">

**Author:** ![Shmuel.Bouhnik](https://avatars.discourse-cdn.com/v4/letter/s/ed8c4c/32.png) [@Shmuel.Bouhnik](https://discuss.elastic.co/u/Shmuel.Bouhnik)\
**Post date:** [February 1, 2017, 3:00pm UTC](https://discuss.elastic.co/t/filebeat-in-windows-and-logstash-in-linux/73529/5 "2017-02-01T15:00:22Z")

</div>

[2017-02-01T14:44:22,184][DEBUG][logstash.pipeline] filter received {"event"=\>{"@timestamp"=\>2017-02-01T14:44:22.178Z, "@version"=\>"1", "message"=\>"\u0000D\u0000E\u0000B\u0000U\u0000G\u0000 \u00002\u00000\u00001\u00007\u0000-\u00000\u00001\u0000-\u00002\u00005\u0000 \u00002\u00002\u0000:\u00004\u00008\u0000:\u00004\u00000\u0000,\u00001\u00008\u00005\u0000 \u0000c\u0000l\u0000a\u0000s\u0000s\u0000:\u0000G\u0000a\u0000t\u0000e\u0000w\u0000a\u0000y\u0000s\u0000\_\u0000J\u0000s\u0000o\u0000n\u0000P\u0000o\u0000s\u0000t\u0000G\u0000W\u0000 \u0000t\u0000o\u0000p\u0000i\u0000c\u0000:\u0000n\u0000u\u0000l\u0000l\u0000 \u0000m\u0000e\u0000t\u0000h\u0000o\u0000d\u0000:\u0000O\u0000n\u0000L\u0000o\u0000a\u0000d\u0000 \u0000s\u0000e\u0000r\u0000v\u0000e\u0000r\u0000:\u0000I\u0000P\u0000-\u00000\u0000A\u00000\u00000\u00000\u00001\u0000F\u00008\u0000 \u0000i\u0000p\u0000:\u00001\u00000\u0000.\u00000\u0000.\u00002\u0000.\u00005\u0000 \u0000r\u0000e\u0000q\u0000i\u0000d\u0000:\u0000f\u0000f\u00003\u00005\u0000f\u00008\u0000a\u00006\u0000-\u00007\u00001\u00003\u00005\u0000-\u00004\u00003\u00005\u00009\u0000-\u0000a\u0000c\u00009\u00007\u0000-\u00004\u0000e\u00009\u00007\u0000d\u0000a\u00000\u00004\u0000b\u00007\u0000a\u00003\u0000 \u0000p\u0000a\u0000r\u0000t\u0000n\u0000e\u0000r\u0000:\u00004\u00003\u00006\u0000 \u0000a\u0000c\u0000t\u0000i\u0000o\u0000n\u0000:\u0000G\u0000e\u0000t\u0000M\u0000e\u0000d\u0000i\u0000a\u0000I\u0000n\u0000f\u0000o\u0000 \u0000u\u0000i\u0000d\u0000:\u00000\u0000 \u0000m\u0000s\u0000g\u0000:\u0000A\u0000P\u0000I\u0000 \u0000R\u0000e\u0000q\u0000u\u0000e\u0000s\u0000t\u0000 \u0000-\u0000\r\u0000\n\u0000D\u0000E\u0000B\u0000U\u0000G\u0000 \u00002\u00000\u00001\u00007\u0000-\u00000\u00001\u0000-\u00002\u00005\u0000 \u00002\u00002\u0000:\u00004\u00008\u0000:\u00004\u00000\u0000,\u00001\u00008\u00005\u0000 \u0000c\u0000l\u0000a\u0000s\u0000s\u0000:\u0000G\u0000a\u0000t\u0000e\u0000w\u0000a\u0000y\u0000s\u0000\_\u0000J\u0000s\u0000o\u0000n\u0000P\u0000o\u0000s\u0000t\u0000G\u0000W\u0000 \u0000t\u0000o\u0000p\u0000i\u0000c\u0000:\u0000n\u0000u\u0000l\u0000l\u0000 \u0000m\u0000e\u0000t\u0000h\u0000o\u0000d\u0000:\u0000O\u0000n\u0000L\u0000o\u0000a\u0000d\u0000 \u0000s\u0000e\u0000r\u0000v\u0000e\u0000r\u0000:\u0000I\u0000P\u0000-\u00000\u0000A\u00000\u00000\u00000\u00001\u0000F\u00008\u0000 \u0000i\u0000p\u0000:\u00001\u00000\u0000.\u00000\u0000.\u00002\u0000.\u00005\u0000 \u0000r\u0000e\u0000q\u0000i\u0000d\u0000:\u0000f\u0000f\u00003\u00005\u0000f\u00008\u0000a\u00006\u0000-\u00007\u00001\u00003\u00005\u0000-\u00004\u00003\u00005\u00009\u0000-\u0000a\u0000c\u00009\u00007\u0000-\u00004\u0000e\u00009\u00007\u0000d\u0000a\u00000\u00004\u0000b\u00007\u0000a\u00003\u0000 \u0000p\u0000a\u0000r\u0000t\u0000n\u0000e\u0000r\u0000:\u00004\u00003\u00006\u0000 \u0000a\u0000c\u0000t\u0000i\u0000o\u0000n\u0000:\u0000G\u0000e\u0000t\u0000M\u0000e\u0000d\u0000i\u0000a\u0000I\u0000n\u0000f\u0000o\u0000 \u0000u\u0000i\u0000d\u0000:\u00000\u0000 \u0000m\u0000s\u0000g\u0000:\u0000A\u0000P\u0000I\u0000 \u0000R\u0000e\u0000q\u0000u\u0000e\u0000s\u0000t\u0000 \u0000-\u0000\r\u0000", "tags"=\>["multiline"]}}

---

<div class="post-metadata">

**Author:** ![Shmuel.Bouhnik](https://avatars.discourse-cdn.com/v4/letter/s/ed8c4c/32.png) [@Shmuel.Bouhnik](https://discuss.elastic.co/u/Shmuel.Bouhnik)\
**Post date:** [February 1, 2017, 3:01pm UTC](https://discuss.elastic.co/t/filebeat-in-windows-and-logstash-in-linux/73529/6 "2017-02-01T15:01:35Z")

</div>

[2017-02-01T14:44:22,185][DEBUG][logstash.filters.grok] Running grok filter {:event=\>2017-02-01T14:44:22.178Z %{host} ...  
[2017-02-01T14:44:22,190][DEBUG][logstash.pipeline] output received {"event"=\>{"@timestamp"=\>2017-02-01T14:44:22.178Z, "@version"=\>"1", "message"=\>"\u0000D\u0000E\u0000B\u0000U\u0000G\u0000 \u00002\u00000\u00001\u00007\u0000-\u00000\u00001\u0000-\u00002\u00005\u0000 \u00002\u00002\u0000:\u00004\u00008\u0000:\u00004\u00000\u0000,\u00001\u00008\u00005\u0000 \u0000c\u0000l\u0000a\u0000s\u0000s\u0000:\u0000G\u0000a\u0000t\u0000e\u0000w\u0000a\u0000y\u0000s\u0000\_\u0000J\u0000s\u0000o\u0000n\u0000P\u0000o\u0000s\u0000t\u0000G\u0000W\u0000 \u0000t\u0000o\u0000p\u0000i\u0000c\u0000:\u0000n\u0000u\u0000l\u0000l\u0000 \u0000m\u0000e\u0000t\u0000h\u0000o\u0000d\u0000:\u0000O\u0000n\u0000L\u0000o\u0000a\u0000d\u0000 \u0000s\u0000e\u0000r\u0000v\u0000e\u0000r\u0000:\u0000I\u0000P\u0000-\u00000\u0000A\u00000\u00000\u00000\u00001\u0000F\u00008\u0000 \u0000i\u0000p\u0000:\u00001\u00000\u0000.\u00000\u0000.\u00002\u0000.\u00005\u0000 \u0000r\u0000e\u0000q\u0000i\u0000d\u0000:\u0000f\u0000f\u00003\u00005\u0000f\u00008\u0000a\u00006\u0000-\u00007\u00001\u00003\u00005\u0000-\u00004\u00003\u00005\u00009\u0000-\u0000a\u0000c\u00009\u00007\u0000-\u00004\u0000e\u00009\u00007\u0000d\u0000a\u00000\u00004\u0000b\u00007\u0000a\u00003\u0000 \u0000p\u0000a\u0000r\u0000t\u0000n\u0000e\u0000r\u0000:\u00004\u00003\u00006\u0000 \u0000a\u0000c\u0000t\u0000i\u0000o\u0000n\u0000:\u0000G\u0000e\u0000t\u0000M\u0000e\u0000d\u0000i\u0000a\u0000I\u0000n\u0000f\u0000o\u0000 \u0000u\u0000i\u0000d\u0000:\u00000\u0000 \u0000m\u0000s\u0000g\u0000:\u0000A\u0000P\u0000I\u0000 \u0000R\u0000e\u0000q\u0000u\u0000e\u0000s\u0000t\u0000 \u0000-\u0000\r\u0000\n\u0000D\u0000E\u0000B\u0000U\u0000G\u0000 \u00002\u00000\u00001\u00007\u0000-\u00000\u00001\u0000-\u00002\u00005\u0000 \u00002\u00002\u0000:\u00004\u00008\u0000:\u00004\u00000\u0000,\u00001\u00008\u00005\u0000 \u0000c\u0000l\u0000a\u0000s\u0000s\u0000:\u0000G\u0000a\u0000t\u0000e\u0000w\u0000a\u0000y\u0000s\u0000\_\u0000J\u0000s\u0000o\u0000n\u0000P\u0000o\u0000s\u0000t\u0000G\u0000W\u0000 \u0000t\u0000o\u0000p\u0000i\u0000c\u0000:\u0000n\u0000u\u0000l\u0000l\u0000 \u0000m\u0000e\u0000t\u0000h\u0000o\u0000d\u0000:\u0000O\u0000n\u0000L\u0000o\u0000a\u0000d\u0000 \u0000s\u0000e\u0000r\u0000v\u0000e\u0000r\u0000:\u0000I\u0000P\u0000-\u00000\u0000A\u00000\u00000\u00000\u00001\u0000F\u00008\u0000 \u0000i\u0000p\u0000:\u00001\u00000\u0000.\u00000\u0000.\u00002\u0000.\u00005\u0000 \u0000r\u0000e\u0000q\u0000i\u0000d\u0000:\u0000f\u0000f\u00003\u00005\u0000f\u00008\u0000a\u00006\u0000-\u00007\u00001\u00003\u00005\u0000-\u00004\u00003\u00005\u00009\u0000-\u0000a\u0000c\u00009\u00007\u0000-\u00004\u0000e\u00009\u00007\u0000d\u0000a\u00000\u00004\u0000b\u00007\u0000a\u00003\u0000 \u0000p\u0000a\u0000r\u0000t\u0000n\u0000e\u0000r\u0000:\u00004\u00003\u00006\u0000 \u0000a\u0000c\u0000t\u0000i\u0000o\u0000n\u0000:\u0000G\u0000e\u0000t\u0000M\u0000e\u0000d\u0000i\u0000a\u0000I\u0000n\u0000f\u0000o\u0000 \u0000u\u0000i\u0000d\u0000:\u00000\u0000 \u0000m\u0000s\u0000g\u0000:\u0000A\u0000P\u0000I\u0000 \u0000R\u0000e\u0000q\u0000u\u0000e\u0000s\u0000t\u0000 \u0000-\u0000\r\u0000", "tags"=\>["multiline", "\_grokparsefailure"]}}

---

<div class="post-metadata">

**Author:** ![Shmuel.Bouhnik](https://avatars.discourse-cdn.com/v4/letter/s/ed8c4c/32.png) [@Shmuel.Bouhnik](https://discuss.elastic.co/u/Shmuel.Bouhnik)\
**Post date:** [February 1, 2017, 3:02pm UTC](https://discuss.elastic.co/t/filebeat-in-windows-and-logstash-in-linux/73529/7 "2017-02-01T15:02:11Z")

</div>

And the line sent is:  
DEBUG 2017-01-25 22:48:40,185 class:Gateways\_JsonPostGW topic:null method:OnLoad server:IP-0A0001F8 ip:10.0.2.5 reqid:ff35f8a6-7135-4359-ac97-4e97da04b7a3 partner:436 action:GetMediaInfo uid:0 msg:API Request -

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [February 1, 2017, 3:07pm UTC](https://discuss.elastic.co/t/filebeat-in-windows-and-logstash-in-linux/73529/8 "2017-02-01T15:07:12Z")

</div>

Isn't this a UTF-16 file? It looks like you should set Filebeat's `encoding` option to utf-16be.

---

<div class="post-metadata">

**Author:** ![Shmuel.Bouhnik](https://avatars.discourse-cdn.com/v4/letter/s/ed8c4c/32.png) [@Shmuel.Bouhnik](https://discuss.elastic.co/u/Shmuel.Bouhnik)\
**Post date:** [February 1, 2017, 3:19pm UTC](https://discuss.elastic.co/t/filebeat-in-windows-and-logstash-in-linux/73529/9 "2017-02-01T15:19:33Z")

</div>

I have set the encoding in the input but not in the output:  
filebeat.prospectors:

- input\_type: log  
paths:
  - D:\Logs\v4\_1\tvp\_api\*.log  
encoding: plain  
ignore\_older: 24h  
document\_type: ws\_log  
multiline.pattern: '^DEBUG'  
multiline.negate: true  
multiline.match: after  
tail\_files: false  
hosts: ["localhost:9200"]  
output.logstash:  
enabled: true  
hosts: ["35.157.114.116:7002"]  
loadbalance: true

output.file:  
enabled: false  
path: D:\Logs\filebeat  
filename: filebeat\_out  
number\_of\_files: 7  
logging.level: debug  
logging.to\_syslog: false  
logging.to\_files: true  
logging.files:  
path: D:\Logs\filebeat  
name: filebeat  
rotateeverybytes: 10485760 # = 10MB  
keepfiles: 10

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [February 1, 2017, 3:29pm UTC](https://discuss.elastic.co/t/filebeat-in-windows-and-logstash-in-linux/73529/10 "2017-02-01T15:29:53Z")

</div>

Setting `encoding` to plain won't do any good. As I said you should probably use utf-16be.

---

<div class="post-metadata">

**Author:** ![Shmuel.Bouhnik](https://avatars.discourse-cdn.com/v4/letter/s/ed8c4c/32.png) [@Shmuel.Bouhnik](https://discuss.elastic.co/u/Shmuel.Bouhnik)\
**Post date:** [February 1, 2017, 3:39pm UTC](https://discuss.elastic.co/t/filebeat-in-windows-and-logstash-in-linux/73529/11 "2017-02-01T15:39:09Z")

</div>

> [@magnusbaeck](#):
>
> utf-16be

I have set it in filebeat and in the logstash see below the configuration file:  
input {  
tcp {  
port =\> 7002  
codec =\> multiline {  
pattern =\> "^(DEBUG|INFO|ERROR|TRACE|WARN|FATAL)"  
negate =\> "true"  
what =\> "previous"  
charset =\> "UTF-16BE"  
}  
}  
}  
filter {  
grok {  
match =\> {  
message =\> "^%{LOGLEVEL:logLevel} %{TIMESTAMP\_ISO8601:sourceTimestamp} class:%{DATA:class} topic:%{DATA:topic} method:%{DATA:method} server:%{DATA:server} ip:%{IPORHOST:ip} reqid:%{DATA:reqid} partner:%{DATA:partner} action:%{DATA:action} uid:%{NUMBER:userId} msg:%{GREEDYDATA:msg}"  
}  
remove\_field =\> ["count", "fields", "offset", "message"]  
}

# date {

# match =\> ["sourceTimestamp", "yyyy-MM-dd HH:mm:ss,SSS"]

# target =\> "@timestamp"

# remove\_field =\> ["sourceTimestamp", "message"]

# }

}  
output {  
elasticsearch {  
hosts =\> ["elastic:9200"]  
index =\> "ott-logs-%{+YYYY.MM.dd}"  
}  
}

---

<div class="post-metadata">

**Author:** ![Shmuel.Bouhnik](https://avatars.discourse-cdn.com/v4/letter/s/ed8c4c/32.png) [@Shmuel.Bouhnik](https://discuss.elastic.co/u/Shmuel.Bouhnik)\
**Post date:** [February 1, 2017, 3:40pm UTC](https://discuss.elastic.co/t/filebeat-in-windows-and-logstash-in-linux/73529/12 "2017-02-01T15:40:23Z")

</div>

I have got Chinese character and it's still not working:  
[2017-02-01T15:37:14,622][DEBUG][logstash.pipeline] filter received {"event"=\>{"@timestamp"=\>2017-02-01T15:37:14.613Z, "port"=\>64109, "@version"=\>"1", "host"=\>"52.19.166.128", "message"=\>"㉗\u0000\u0001㉃\u0000ŷ硞泐八�【߰衻뚌摛煲俭�ᙒ㨖웆怘쳅㺻˛刭㦥葼蟑瑻嫟\u0E8E믿뭟굖㞫헍�踜ꦥ䢀枈⾞ǡ㧔菫ↁ⍓҄츎籤詰䧠㛚酃ꓑ͂ꙴ⥕⚕ﺮ෦ᦚ䶪췺ᜤნ㈷꿋㹢唽렾哕ꦨ畕얓꿉�次쥛嚶籜充뢆몮ଜǳ㰯쫤㾓鷼ያ뿒랉酃ꃾ\u1AF6辝硣榙ᦑ敘沰傉�ᣑఔˮ⣲㎽蓺㺸䋜ﴔ텹�ಃᠹ㺺ᚿ丏蹚ᅸ㻱賻荔睊⧽礣걇굒镦ꤑ㌿�ᚻ⸷�蛖닔릑䕮뚒驭⤋�阭ꧢ塒⸼쵱譼ⶨ觖\u4DB8蕛䯻ꥳ抱\u2D2Aㆆữ\u0E7B鼖๑䡈稼썄跖쭿ᙈ藸滣쑳끮Ȅ鏪㒃쯥伀\u0000\uFFFF席飊"}}  
[2017-02-01T15:37:14,624][DEBUG][logstash.filters.grok] Running grok filter {:event=\>2017-02-01T15:37:14.613Z 52.19.166.128 ㉗㉃ŷ硞泐八�【߰衻뚌摛煲俭�ᙒ㨖웆怘쳅㺻˛刭㦥葼蟑瑻嫟ຎ믿뭟굖㞫헍�踜ꦥ䢀枈⾞ǡ㧔菫ↁ⍓҄츎籤詰䧠㛚酃ꓑ͂ꙴ⥕⚕ﺮ෦ᦚ䶪췺ᜤნ㈷꿋㹢唽렾哕ꦨ畕얓꿉�次쥛嚶籜充뢆몮ଜǳ㰯쫤㾓鷼ያ뿒랉酃ꃾ᫶辝硣榙ᦑ敘沰傉�ᣑఔˮ⣲㎽蓺㺸䋜ﴔ텹�ಃᠹ㺺ᚿ丏蹚ᅸ㻱賻荔睊⧽礣걇굒镦ꤑ㌿�ᚻ⸷�蛖닔릑䕮뚒驭⤋�阭ꧢ塒⸼쵱譼ⶨ觖䶸蕛䯻ꥳ抱⴪ㆆữ๻鼖๑䡈稼썄跖쭿ᙈ藸滣쑳끮Ȅ鏪㒃쯥伀▒席飊}  
[2017-02-01T15:37:14,628][DEBUG][logstash.filters.grok] Event now: {:event=\>2017-02-01T15:37:14.613Z 52.19.166.128 ㉗㉃ŷ硞泐八�【߰衻뚌摛煲俭�ᙒ㨖웆怘쳅㺻˛刭㦥葼蟑瑻嫟ຎ믿뭟굖㞫헍�踜ꦥ䢀枈⾞ǡ㧔菫ↁ⍓҄츎籤詰䧠㛚酃ꓑ͂ꙴ⥕⚕ﺮ෦ᦚ䶪췺ᜤნ㈷꿋㹢唽렾哕ꦨ畕얓꿉�次쥛嚶籜充뢆몮ଜǳ㰯쫤㾓鷼ያ뿒랉酃ꃾ᫶辝硣榙ᦑ敘沰傉�ᣑఔˮ⣲㎽蓺㺸䋜ﴔ텹�ಃᠹ㺺ᚿ丏蹚ᅸ㻱賻荔睊⧽礣걇굒镦ꤑ㌿�ᚻ⸷�蛖닔릑䕮뚒驭⤋�阭ꧢ塒⸼쵱譼ⶨ觖䶸蕛䯻ꥳ抱⴪ㆆữ๻鼖๑䡈稼썄跖쭿ᙈ藸滣쑳끮Ȅ鏪㒃쯥伀▒席飊}  
[2017-02-01T15:37:14,634][DEBUG][logstash.pipeline] output received {"event"=\>{"@timestamp"=\>2017-02-01T15:37:14.613Z, "port"=\>64109, "@version"=\>"1", "host"=\>"52.19.166.128", "message"=\>"㉗\u0000\u0001㉃\u0000ŷ硞泐八�【߰衻뚌摛煲俭�ᙒ㨖웆怘쳅㺻˛刭㦥葼蟑瑻嫟\u0E8E믿뭟굖㞫헍�踜ꦥ䢀枈⾞ǡ㧔菫ↁ⍓҄츎籤詰䧠㛚酃ꓑ͂ꙴ⥕⚕ﺮ෦ᦚ䶪췺ᜤნ㈷꿋㹢唽렾哕ꦨ畕얓꿉�次쥛嚶籜充뢆몮ଜǳ㰯쫤㾓鷼ያ뿒랉酃ꃾ\u1AF6辝硣榙ᦑ敘沰傉�ᣑఔˮ⣲㎽蓺㺸䋜ﴔ텹�ಃᠹ㺺ᚿ丏蹚ᅸ㻱賻荔睊⧽礣걇굒镦ꤑ㌿�ᚻ⸷�蛖닔릑䕮뚒驭⤋�阭ꧢ塒⸼쵱譼ⶨ觖\u4DB8蕛䯻ꥳ抱\u2D2Aㆆữ\u0E7B鼖๑䡈稼썄跖쭿ᙈ藸滣쑳끮Ȅ鏪㒃쯥伀\u0000\uFFFF席飊", "tags"=\>["\_grokparsefailure"]}}

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 1, 2017, 3:40pm UTC](https://discuss.elastic.co/t/filebeat-in-windows-and-logstash-in-linux/73529/13 "2017-03-01T15:40:28Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
