# \[HELP winlogbeat.yml\] How to send Removable storage logs to Elasticsearch

**URL:** <https://discuss.elastic.co/t/help-winlogbeat-yml-how-to-send-removable-storage-logs-to-elasticsearch/344738>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [October 10, 2023, 12:54pm UTC](https://discuss.elastic.co/t/help-winlogbeat-yml-how-to-send-removable-storage-logs-to-elasticsearch/344738 "2023-10-10T12:54:32Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![YUUTA.INOUE-JPN](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yuuta.inoue-jpn/32/117963_2.png) [@YUUTA.INOUE-JPN](https://discuss.elastic.co/u/YUUTA.INOUE-JPN)\
**Post date:** [October 10, 2023, 12:54pm UTC](https://discuss.elastic.co/t/help-winlogbeat-yml-how-to-send-removable-storage-logs-to-elasticsearch/344738/1 "2023-10-10T12:54:32Z")

</div>

Hello from Japan  
I have a question for you respected engineers.  
I am an inexperienced Japanese engineer with Elastic search.  
I have installed winlogbeat on my Windows PC and have built an environment to send Windows logs to elasticsearch for analysis by kibana.

I want to send Removable storage logs to Elasticsearch.  
I confirmed that Event ID 4663 in the security item in the Windows event viewer is a removable storage log.  
So I created and implemented a yml file like the one below.

```auto
winlogbeat.event_logs:
   - name: Security
     event_id: 4663

```

However, Event ID 4663 also outputs logs other than USB.  
In addition, it is known that this yml file also sends logs other than Removable storage to Elasticsearch.

How should I write the yml to send logs to Elasticsearch with the event ID 4663 and task category Removable Storage in the Windows Event viewer?

I would like help from all of you respected ELASTIC engineers.

I await your replies and information.  
Thank you

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [October 10, 2023, 4:00pm UTC](https://discuss.elastic.co/t/help-winlogbeat-yml-how-to-send-removable-storage-logs-to-elasticsearch/344738/2 "2023-10-10T16:00:39Z")

</div>

If you are only interested in that one event with a particular attribute then I recommend to go the advanced route with a XML query. See [Configure Winlogbeat | Winlogbeat Reference [8.10] | Elastic](https://www.elastic.co/guide/en/beats/winlogbeat/current/configuration-winlogbeat-options.html#_event_logs_xml_query).

Use the Windows Event Viewer to create a custom view that only includes the specific logs that you want. Then put that view's XML query into the config file.

[Advanced XML filtering in the Windows Event Viewer - Microsoft Community Hub](https://techcommunity.microsoft.com/t5/ask-the-directory-services-team/advanced-xml-filtering-in-the-windows-event-viewer/ba-p/399761) has good examples too.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 7, 2023, 6:01pm UTC](https://discuss.elastic.co/t/help-winlogbeat-yml-how-to-send-removable-storage-logs-to-elasticsearch/344738/3 "2023-11-07T18:01:25Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
