# How to get logs of company in one system?

**URL:** <https://discuss.elastic.co/t/how-to-get-logs-of-company-in-one-system/172904>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [March 19, 2019, 7:14am UTC](https://discuss.elastic.co/t/how-to-get-logs-of-company-in-one-system/172904 "2019-03-19T07:14:53Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Kajol\_Nimesh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kajol_nimesh/32/42291_2.png) [@Kajol\_Nimesh](https://discuss.elastic.co/u/Kajol_Nimesh)\
**Post date:** [March 19, 2019, 7:14am UTC](https://discuss.elastic.co/t/how-to-get-logs-of-company-in-one-system/172904/1 "2019-03-19T07:14:53Z")

</div>

Hi,  
I'm new to ELK Stack and I want to know that how can I get logs of multiple systems of company on my system. Do I need to install filebeat or Winlogbeat on each system or is there any other way to do it? I'm unable to find the ways online. Please help.

---

<div class="post-metadata">

**Author:** ![adrisr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/adrisr/32/25423_2.png) [@adrisr](https://discuss.elastic.co/u/adrisr)\
**Post date:** [March 21, 2019, 4:45pm UTC](https://discuss.elastic.co/t/how-to-get-logs-of-company-in-one-system/172904/2 "2019-03-21T16:45:36Z")

</div>

Hi,

The beats that you use depend on the kind of logs that you want to ingest. Winlogbeat is used to read events from Windows Event Logs, so it's used in Windows systems if your application uses this facility for logging.

Filebeat reads logs from log files or via the network using the syslog protocol.

You're going to need to install both in every system and point them to the log files / event log that you want to process.

---

<div class="post-metadata">

**Author:** ![Kajol\_Nimesh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kajol_nimesh/32/42291_2.png) [@Kajol\_Nimesh](https://discuss.elastic.co/u/Kajol_Nimesh)\
**Post date:** [March 26, 2019, 8:38am UTC](https://discuss.elastic.co/t/how-to-get-logs-of-company-in-one-system/172904/3 "2019-03-26T08:38:57Z")

</div>

Thanku Sir 🙂

---

<div class="post-metadata">

**Author:** ![jwahlgren](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jwahlgren/32/40220_2.png) [@jwahlgren](https://discuss.elastic.co/u/jwahlgren)\
**Post date:** [April 2, 2019, 10:02am UTC](https://discuss.elastic.co/t/how-to-get-logs-of-company-in-one-system/172904/4 "2019-04-02T10:02:21Z")

</div>

For the Windows logs I would suggest to make use of Windows Event Forwarding (WEF) for centralized log collection. No need to install Winlogbeat on every Windows endpoint. In the Winlogbeat configuration file you can then specify:

```
winlogbeat.event_logs:
 - name: ForwardedEvents
 ignore_older: 72h

```

Microsoft Docs: [https://docs.microsoft.com/en-us/windows/desktop/WEC/windows-event-collector](https://docs.microsoft.com/en-us/windows/desktop/WEC/windows-event-collector)

Video: [https://youtu.be/BXflPu7zqLM](https://youtu.be/BXflPu7zqLM)

NSA Whitepaper (section 2.3): [https://apps.nsa.gov/iaarchive/library/reports/spotting-the-adversary-with-windows-event-log-monitoring.cfm](https://apps.nsa.gov/iaarchive/library/reports/spotting-the-adversary-with-windows-event-log-monitoring.cfm)

---

<div class="post-metadata">

**Author:** ![Kajol\_Nimesh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kajol_nimesh/32/42291_2.png) [@Kajol\_Nimesh](https://discuss.elastic.co/u/Kajol_Nimesh)\
**Post date:** [April 2, 2019, 10:18am UTC](https://discuss.elastic.co/t/how-to-get-logs-of-company-in-one-system/172904/5 "2019-04-02T10:18:00Z")

</div>

Thank You

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 30, 2019, 10:18am UTC](https://discuss.elastic.co/t/how-to-get-logs-of-company-in-one-system/172904/6 "2019-04-30T10:18:00Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
