# How to run Powershell Scripts with Elastic?

**URL:** <https://discuss.elastic.co/t/how-to-run-powershell-scripts-with-elastic/357224>\
**Category:** Kibana\
**Created:** [April 11, 2024, 2:35pm UTC](https://discuss.elastic.co/t/how-to-run-powershell-scripts-with-elastic/357224 "2024-04-11T14:35:40Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![erikg](https://avatars.discourse-cdn.com/v4/letter/e/91b2a8/32.png) [@erikg](https://discuss.elastic.co/u/erikg)\
**Post date:** [April 11, 2024, 2:35pm UTC](https://discuss.elastic.co/t/how-to-run-powershell-scripts-with-elastic/357224/1 "2024-04-11T14:35:40Z")

</div>

Hello,

I was wondering if possible to automate a powershell script with Elastic.

Perhaps a trigger can set off the script to run?  
I read that webhooks might be an option but is there better methods?

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [April 11, 2024, 2:52pm UTC](https://discuss.elastic.co/t/how-to-run-powershell-scripts-with-elastic/357224/2 "2024-04-11T14:52:46Z")

</div>

It's possible in Logstash by using the [exec plugin](https://www.elastic.co/guide/en/logstash/current/plugins-inputs-exec.html). ES and Kib don't support AFAIK.

---

<div class="post-metadata">

**Author:** ![erikg](https://avatars.discourse-cdn.com/v4/letter/e/91b2a8/32.png) [@erikg](https://discuss.elastic.co/u/erikg)\
**Post date:** [April 11, 2024, 4:46pm UTC](https://discuss.elastic.co/t/how-to-run-powershell-scripts-with-elastic/357224/3 "2024-04-11T16:46:37Z")

</div>

Hey @Rios based on that documentation it seems like you can only run a command? would the command be to run

```auto
.\run_script.ps1

```

Also I don't want to run this all the time, I was thinking if there is a way to trigger the command?

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [April 11, 2024, 5:01pm UTC](https://discuss.elastic.co/t/how-to-run-powershell-scripts-with-elastic/357224/4 "2024-04-11T17:01:35Z")

</div>

> [@erikg](#):
>
> it seems like you can only run a command? would the command be to run

You need to pass the full path of your script.

Also, keep in mind that this will execute the script and pass the result into the logstash pipeline and it will be processed by other filters and sent to the configured output.

You cannot trigger this, you need to configure the filter to run on a pre-determined interval or on a schedule.

What you can is to have a conditional in your configuration that will run the script based on the value of the field on some event being processed by the same pipeline.

What you want to achieve with this? It is not clear what is your use case.

---

<div class="post-metadata">

**Author:** ![erikg](https://avatars.discourse-cdn.com/v4/letter/e/91b2a8/32.png) [@erikg](https://discuss.elastic.co/u/erikg)\
**Post date:** [April 11, 2024, 6:43pm UTC](https://discuss.elastic.co/t/how-to-run-powershell-scripts-with-elastic/357224/5 "2024-04-11T18:43:52Z")

</div>

@leandrojmp

Thanks for the information!

The goal is that using the data being ingested into Elastic to trigger a PowerShell script to run.

I could trigger the alert by data being processed by the same pipeline running the script?  
if so that could work as the data in particular to my use case is being ingested through logstash

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [April 11, 2024, 7:43pm UTC](https://discuss.elastic.co/t/how-to-run-powershell-scripts-with-elastic/357224/6 "2024-04-11T19:43:25Z")

</div>

Leandro provided you with info how to use the plugin.

Few more info for options how to use.

1. Logstash. If you already have the PS script, which collect data and output is in JSON, CSV, etc. LS is useful, especially need to filter data, you can use LS as a scheduler/cron. Every a minute, hour, day.... This approach is ideal in case the script already generated data in mentioned formats, you need just to import, with(out) minor data changes.

2. PS Script. You can write your own PS script, collect data from somewhere and directly insert data in ES by using [Invoke-WebRequest](https://lukemerrett.com/getting-started-with-elasticsearch/), and write data as JSON. In that case, use Windows TaskScheduler to trigger or you can run PS manually. Totally versatile, you can integrate abs. everything with ES, especially MS products.

3. ES [cmdlets](https://github.com/elastic/powershell/tree/master/Elastic.Console). There is Elastic.Console module, will provide cmdlets for PS -\>ES request.

---

<div class="post-metadata">

**Author:** ![erikg](https://avatars.discourse-cdn.com/v4/letter/e/91b2a8/32.png) [@erikg](https://discuss.elastic.co/u/erikg)\
**Post date:** [April 11, 2024, 9:35pm UTC](https://discuss.elastic.co/t/how-to-run-powershell-scripts-with-elastic/357224/7 "2024-04-11T21:35:29Z")

</div>

> [@Rios](#):
>
> If you already have the PS script, which collect data and output is in JSON, CSV, etc. LS is useful, especially need to filter data, you can use LS as a scheduler/cron. Every a minute, hour, day.... This approach is ideal in case the script already generated data in mentioned formats, you need just to import, with(out) minor data changes.

Hey @Rios this is great information, but I am not ingesting data from a PS script, I am trying to trigger a script using Elastic's data. The issue is that this isn't a continuous script that needs to be run. The script should only been run if an event occurs.

---

<div class="post-metadata">

**Author:** ![erikg](https://avatars.discourse-cdn.com/v4/letter/e/91b2a8/32.png) [@erikg](https://discuss.elastic.co/u/erikg)\
**Post date:** [April 11, 2024, 10:24pm UTC](https://discuss.elastic.co/t/how-to-run-powershell-scripts-with-elastic/357224/8 "2024-04-11T22:24:35Z")

</div>

@Rios @leandrojmp

AFter digging in Elastic github, This is what I am talking about:  
[Shell script and powershell connector for watcher alerts · Issue #105381 · elastic/kibana (github.com)](https://github.com/elastic/kibana/issues/105381)

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [April 11, 2024, 11:08pm UTC](https://discuss.elastic.co/t/how-to-run-powershell-scripts-with-elastic/357224/9 "2024-04-11T23:08:24Z")

</div>

> [@erikg](#):
>
> I am trying to trigger a script using Elastic's data. The issue is that this isn't a continuous script that needs to be run. The script should only been run if an event occurs.

None of the tools in the stack currently support doings this, but it is quite easy to do that outside Elastic or Logstash, you just need to query elastic and then run your script.

I have a couple of python script that do exactly this, query a specific index for a specific event and if this is found it will trigger other actions.

You also have third party tools, like ElastAlert2 that makes it even easier: [Alerts — ElastAlert 2 0.0.1 documentation](https://elastalert2.readthedocs.io/en/latest/alerts.html#command)

---

<div class="post-metadata">

**Author:** ![erikg](https://avatars.discourse-cdn.com/v4/letter/e/91b2a8/32.png) [@erikg](https://discuss.elastic.co/u/erikg)\
**Post date:** [April 12, 2024, 2:14pm UTC](https://discuss.elastic.co/t/how-to-run-powershell-scripts-with-elastic/357224/10 "2024-04-12T14:14:10Z")

</div>

Thanks for the help! @leandrojmp @Rios
