# How can ship logs to Logstash using Windows Events?

**URL:** <https://discuss.elastic.co/t/how-can-ship-logs-to-logstash-using-windows-events/27644>\
**Category:** Logstash\
**Created:** [August 19, 2015, 7:42am UTC](https://discuss.elastic.co/t/how-can-ship-logs-to-logstash-using-windows-events/27644 "2015-08-19T07:42:37Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![thyfere](https://avatars.discourse-cdn.com/v4/letter/t/48db29/32.png) [@thyfere](https://discuss.elastic.co/u/thyfere)\
**Post date:** [August 19, 2015, 7:42am UTC](https://discuss.elastic.co/t/how-can-ship-logs-to-logstash-using-windows-events/27644/1 "2015-08-19T07:42:37Z")

</div>

Hi,

I am very new to ELK stack. I have setup a stack using two Windows Server 2012 R2 VM machines, one is for Logstash and other for Kibana and Elastic search. Initially, I was thinking to use nxlog for logs forwarding but I came to know that I may use Windows events as well using group policy.

Can anyone help me in this regard? Please refer me to step by step guide or if anyone has an experience in it, let me know.

Why I don't want to use logstash-forwarder because then I will have to install Java on all of our Servers which I don't want obviously.

Thanks.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [August 19, 2015, 7:59am UTC](https://discuss.elastic.co/t/how-can-ship-logs-to-logstash-using-windows-events/27644/2 "2015-08-19T07:59:13Z")

</div>

> Initially, I was thinking to use nxlog for logs forwarding but I came to know that I may use Windows events as well using group policy.

My Windows-fu isn't strong enough to fully comprehend what you've written, but AFAIK you can pull event logs from a remote machine, in which case you shouldn't have to be dependent on running a log shipping agent on each Windows machine. However, Logstash's [eventlog input plugin](https://www.elastic.co/guide/en/logstash/current/plugins-inputs-eventlog.html) doesn't seem to support this.

> Why I don't want to use logstash-forwarder because then I will have to install Java on all of our Servers which I don't want obviously.

Logstash-forwarder does not have a Java dependency, but Logstash proper does. If you don't want a JVM dependency NxLog seems like a good choice.

---

<div class="post-metadata">

**Author:** ![thyfere](https://avatars.discourse-cdn.com/v4/letter/t/48db29/32.png) [@thyfere](https://discuss.elastic.co/u/thyfere)\
**Post date:** [August 19, 2015, 8:13am UTC](https://discuss.elastic.co/t/how-can-ship-logs-to-logstash-using-windows-events/27644/3 "2015-08-19T08:13:40Z")

</div>

Hi Magnus,

Thanks for your reply. As I am a newbie, this is a news to me that I can pull logs from Windows machine, that's awesome. Then why people use log shipping agents on their computer, I am just curious?

So, could you please refer me to few examples of conf files where users have pulled the logs out of Windows machines. I really need to see the examples of conf files.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [August 19, 2015, 8:26am UTC](https://discuss.elastic.co/t/how-can-ship-logs-to-logstash-using-windows-events/27644/4 "2015-08-19T08:26:01Z")

</div>

As I said, I _think_ Windows itself supports reading event log from remote machines, but _Logstash_ doesn't support it.

---

<div class="post-metadata">

**Author:** ![thyfere](https://avatars.discourse-cdn.com/v4/letter/t/48db29/32.png) [@thyfere](https://discuss.elastic.co/u/thyfere)\
**Post date:** [August 19, 2015, 12:03pm UTC](https://discuss.elastic.co/t/how-can-ship-logs-to-logstash-using-windows-events/27644/5 "2015-08-19T12:03:12Z")

</div>

If I want to ship different kind of logs to logstash, i.e. Windows Event and IIS. Should I mention two different IP addresses and ports in input section of logstash.conf. For example:

input {  
tcp {  
host =\> "127.0.0.1"  
port =\> 3514  
}  
tcp {  
type =\> "eventlog"  
host =\> "10.1.1.2"  
port =\> 3515  
format =\> 'json'  
}  
}

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [August 19, 2015, 1:02pm UTC](https://discuss.elastic.co/t/how-can-ship-logs-to-logstash-using-windows-events/27644/6 "2015-08-19T13:02:43Z")

</div>

Why different IP addresses? Normally you don't set the `host` option for inputs at all.

If you need to use different codecs or set different types you should probably listen on different ports. However, you can also change the type based on the contents of the message. So in the end it depends. What's going to send data on those TCP ports?

---

<div class="post-metadata">

**Author:** ![thyfere](https://avatars.discourse-cdn.com/v4/letter/t/48db29/32.png) [@thyfere](https://discuss.elastic.co/u/thyfere)\
**Post date:** [August 19, 2015, 1:04pm UTC](https://discuss.elastic.co/t/how-can-ship-logs-to-logstash-using-windows-events/27644/7 "2015-08-19T13:04:53Z")

</div>

I want to send Windows Event logs and IIS from our webservers. So, how should the conf file looks like then?

---

<div class="post-metadata">

**Author:** ![thyfere](https://avatars.discourse-cdn.com/v4/letter/t/48db29/32.png) [@thyfere](https://discuss.elastic.co/u/thyfere)\
**Post date:** [August 19, 2015, 1:07pm UTC](https://discuss.elastic.co/t/how-can-ship-logs-to-logstash-using-windows-events/27644/8 "2015-08-19T13:07:45Z")

</div>

Is this code looks good:

input {  
tcp {  
type =\> "WindowsEventLog"  
port =\> 5544  
codec =\> "line"  
}  
}

filter{  
if [type] == "WindowsEventLog" {  
json{  
source =\> "message"  
}  
if [SourceModuleName] == "eventlog" {  
mutate {  
replace =\> ["message", "%{Message}"]  
}  
mutate {  
remove\_field =\> ["Message"]  
}  
}  
}  
}

output {  
elasticsearch {  
host =\> "1.1.1.1"  
protocol =\> "http"  
}  
}

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [August 19, 2015, 2:19pm UTC](https://discuss.elastic.co/t/how-can-ship-logs-to-logstash-using-windows-events/27644/9 "2015-08-19T14:19:41Z")

</div>

The configuration you've showed us is for _receiving_ log messages. What is going to send events _to_ the TCP ports you've defined here?

---

<div class="post-metadata">

**Author:** ![thyfere](https://avatars.discourse-cdn.com/v4/letter/t/48db29/32.png) [@thyfere](https://discuss.elastic.co/u/thyfere)\
**Post date:** [August 19, 2015, 3:53pm UTC](https://discuss.elastic.co/t/how-can-ship-logs-to-logstash-using-windows-events/27644/10 "2015-08-19T15:53:20Z")

</div>

As it's mentioned, Windows event logs will be sent.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [August 19, 2015, 6:10pm UTC](https://discuss.elastic.co/t/how-can-ship-logs-to-logstash-using-windows-events/27644/11 "2015-08-19T18:10:35Z")

</div>

Yes, but what software component sends those messages? I don't believe Windows does it on its own.

---

<div class="post-metadata">

**Author:** ![thyfere](https://avatars.discourse-cdn.com/v4/letter/t/48db29/32.png) [@thyfere](https://discuss.elastic.co/u/thyfere)\
**Post date:** [August 20, 2015, 5:18am UTC](https://discuss.elastic.co/t/how-can-ship-logs-to-logstash-using-windows-events/27644/12 "2015-08-20T05:18:40Z")

</div>

I am using nxlog, here is the contents of conf file:

# Please set the ROOT to the folder your nxlog was installed into,

## otherwise it will not start.

#define ROOT C:\Program Files\nxlog  
define ROOT C:\Program Files (x86)\nxlog

Moduledir %ROOT%\modules  
CacheDir %ROOT%\data  
Pidfile %ROOT%\data\nxlog.pid  
SpoolDir %ROOT%\data  
LogFile %ROOT%\data\nxlog.log

 Module xm\_json
# Nxlog internal logs
 Module im\_internal Exec $EventReceivedTime = integer($EventReceivedTime) / 1000000; to\_json();
# Windows Event Log
# Uncomment im\_msvistalog for Windows Vista/2008 and later Module im\_msvistalog
# Uncomment im\_mseventlog for Windows XP/2000/2003

# Module im\_mseventlog

Exec $EventReceivedTime = integer($EventReceivedTime) / 1000000; to\_json();

 Module om\_tcp Host 1.1.1. Port 5544

\<Route 1\>  
Path internal, eventlog =\> out

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [August 20, 2015, 5:34am UTC](https://discuss.elastic.co/t/how-can-ship-logs-to-logstash-using-windows-events/27644/13 "2015-08-20T05:34:19Z")

</div>

Since you're using `to_json()` in your Nxlog config I'd expect you to want to use the json codec in your Logstash input configuration. But why not try it out? You'll see what codec changes (if any) need to be done.

(Hint: If you format config files as code they'll be sanely rendered and not like above.)

---

<div class="post-metadata">

**Author:** ![thyfere](https://avatars.discourse-cdn.com/v4/letter/t/48db29/32.png) [@thyfere](https://discuss.elastic.co/u/thyfere)\
**Post date:** [August 20, 2015, 6:53am UTC](https://discuss.elastic.co/t/how-can-ship-logs-to-logstash-using-windows-events/27644/14 "2015-08-20T06:53:20Z")

</div>

Yeah but that is only for NXLOG internal logs which I didn't configure in logstash yet because currently I am interested in Windows Events only; therefore, I have used module im\_msvistalog in nxlog.conf.

By the way, which codec is recommended for Windows Events?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [August 20, 2015, 7:08am UTC](https://discuss.elastic.co/t/how-can-ship-logs-to-logstash-using-windows-events/27644/15 "2015-08-20T07:08:54Z")

</div>

> By the way, which codec is recommended for Windows Events?

This question doesn't make sense. Nxlog will read events regardless of source and turn them into its own internal key/value format, which can be rendered as plain text, JSON, or something else when e.g. sent over the network or written to a file. Nxlog's output codec should match Logstash's input codec, that's all.

---

<div class="post-metadata">

**Author:** ![thyfere](https://avatars.discourse-cdn.com/v4/letter/t/48db29/32.png) [@thyfere](https://discuss.elastic.co/u/thyfere)\
**Post date:** [August 22, 2015, 3:16pm UTC](https://discuss.elastic.co/t/how-can-ship-logs-to-logstash-using-windows-events/27644/17 "2015-08-22T15:16:56Z")

</div>

Hi Again,

Thank you for your clarification. I got your point. Now, I am going to change the logging solution design little bit.

- All the Windows Servers will be subscribed to Logstash server that is Windows based too.
- I will install the nxlog on Logstash server that will rendered the local Windows events whereas local Windows events are being shipped from other servers via Windows default event subscription method.

The solution will be look like this (Windows Event Collector will serve as Logstash and nxlog):

![](https://us1.discourse-cdn.com/elastic/original/2X/d/d16fb020376c8276aa5f50d834562bde080c1d0b.jpg)

What do you say about this solution? Any suggestion?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [August 23, 2015, 4:39pm UTC](https://discuss.elastic.co/t/how-can-ship-logs-to-logstash-using-windows-events/27644/18 "2015-08-23T16:39:44Z")

</div>

Sure, that looks reasonable. However:

- It seems you need the non-free version of NXLog to collect eventlogs from remote Windows machines.

- I'm not sure the XP-compatible [im\_mseventlog input](https://nxlog.co/docs/nxlog-ce/nxlog-reference-manual.html#im_mseventlog) supports pulling eventlogs from remote Windows machines.

---

<div class="post-metadata">

**Author:** ![thyfere](https://avatars.discourse-cdn.com/v4/letter/t/48db29/32.png) [@thyfere](https://discuss.elastic.co/u/thyfere)\
**Post date:** [August 23, 2015, 8:30pm UTC](https://discuss.elastic.co/t/how-can-ship-logs-to-logstash-using-windows-events/27644/19 "2015-08-23T20:30:43Z")

</div>

Hi,

No, I will not pull logs from remote machines. U didn't get my point, Logstash is Windows based server which will act as events collector from other Windows machines. Then, I will install nxlog on Logstash server which will render the local logs.Remember, local logs are being pulled or pushed by other source Windows machines; therefore, nxlog doesn't need to pull logs from remote machines, Windows default event subscriber/publisher model will do instead.

---

<div class="post-metadata">

**Author:** ![usahitya](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/usahitya/32/6180_2.png) [@usahitya](https://discuss.elastic.co/u/usahitya)\
**Post date:** [November 26, 2015, 6:59am UTC](https://discuss.elastic.co/t/how-can-ship-logs-to-logstash-using-windows-events/27644/20 "2015-11-26T06:59:41Z")

</div>

could you please share link where I can download Logstash forwarder for Windows?  
is there any Document , how to install in Windows?  
is Logstash forwarder is works with WIndows server 2008R2?

thanks in advance

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [November 26, 2015, 7:06am UTC](https://discuss.elastic.co/t/how-can-ship-logs-to-logstash-using-windows-events/27644/21 "2015-11-26T07:06:17Z")

</div>

logstash-forwarder is deprecated in favor of [Filebeat](https://www.elastic.co/products/beats/filebeat). If you have any follow-up questions about that please start a new thread.

[Next page](https://discuss.elastic.co/t/how-can-ship-logs-to-logstash-using-windows-events/27644.md?page=2)
