# How to send windows 2012 r2 log file to logstash

**URL:** <https://discuss.elastic.co/t/how-to-send-windows-2012-r2-log-file-to-logstash/28708>\
**Category:** Logstash\
**Created:** [September 4, 2015, 10:05pm UTC](https://discuss.elastic.co/t/how-to-send-windows-2012-r2-log-file-to-logstash/28708 "2015-09-04T22:05:52Z")\
**Posts on this page:** 19\
**Page:** 1

<div class="post-metadata">

**Author:** ![Kaufusihm](https://avatars.discourse-cdn.com/v4/letter/k/bcef8e/32.png) [@Kaufusihm](https://discuss.elastic.co/u/Kaufusihm)\
**Post date:** [September 4, 2015, 10:05pm UTC](https://discuss.elastic.co/t/how-to-send-windows-2012-r2-log-file-to-logstash/28708/1 "2015-09-04T22:05:52Z")

</div>

I currently have a logstash server, Elasticsearch server, and kibana server. I am able to send logstash local data using stdin from LS to my ES instance and I can interact with Kibana, but now I am trying to use a windows server 2012 r2 machine to send a log file to Logstash indexer.

Do I need logstash-forwarder (as a shipper)?  
Do I need Redis (a broker)?  
What would my logstash config file look like?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [September 5, 2015, 12:16pm UTC](https://discuss.elastic.co/t/how-to-send-windows-2012-r2-log-file-to-logstash/28708/2 "2015-09-05T12:16:34Z")

</div>

> Do I need logstash-forwarder (as a shipper)?

No, but you _could_ use it.

> Do I need Redis (a broker)?

No, but you _could_ use it.

> What would my logstash config file look like?

You'll have to decide how to transport the messages off of the machine. As mentioned you could indeed have Logstash ship the messages to a Redis broker (using the [redis output](https://www.elastic.co/guide/en/logstash/current/plugins-outputs-redis.html)) and you'd have your central Logstash instance use a [redis input](https://www.elastic.co/guide/en/logstash/current/plugins-inputs-redis.html) to pull those messages.

You could also use the lumberjack protocol to ship the messages directly to the central Logstash instance. Then you'd use a [lumberjack output](https://www.elastic.co/guide/en/logstash/current/plugins-outputs-lumberjack.html) on the Windows box and a [lumberjack input](https://www.elastic.co/guide/en/logstash/current/plugins-inputs-lumberjack.html) on your central instance. The infrastructure for this is slightly less complicated and you could easily replace Logstash on the Windows machine with logstash-forwarder since it support the lumberjack protocol (and only that protocol).

---

<div class="post-metadata">

**Author:** ![Kaufusihm](https://avatars.discourse-cdn.com/v4/letter/k/bcef8e/32.png) [@Kaufusihm](https://discuss.elastic.co/u/Kaufusihm)\
**Post date:** [September 8, 2015, 3:37pm UTC](https://discuss.elastic.co/t/how-to-send-windows-2012-r2-log-file-to-logstash/28708/3 "2015-09-08T15:37:44Z")

</div>

Magnus,

Thanks for the answers! This I believe will help a ton.

Yes, I plan to move forward with lumberjack output/input. For now.

Best,

---

<div class="post-metadata">

**Author:** ![Kaufusihm](https://avatars.discourse-cdn.com/v4/letter/k/bcef8e/32.png) [@Kaufusihm](https://discuss.elastic.co/u/Kaufusihm)\
**Post date:** [September 9, 2015, 4:52pm UTC](https://discuss.elastic.co/t/how-to-send-windows-2012-r2-log-file-to-logstash/28708/4 "2015-09-09T16:52:05Z")

</div>

So I have downloaded and tried to install logstash-forwarder on my server 2012 box, but nothing seems to happen and I check processes and I don't see it running...

What should happen when trying to install logstash-forwarder on windows server machine?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [September 9, 2015, 5:19pm UTC](https://discuss.elastic.co/t/how-to-send-windows-2012-r2-log-file-to-logstash/28708/5 "2015-09-09T17:19:00Z")

</div>

There is no installation of logstash-forwarder. It's just an .exe file that you drop in any directory.

How are you invoking it?

---

<div class="post-metadata">

**Author:** ![Kaufusihm](https://avatars.discourse-cdn.com/v4/letter/k/bcef8e/32.png) [@Kaufusihm](https://discuss.elastic.co/u/Kaufusihm)\
**Post date:** [September 9, 2015, 6:26pm UTC](https://discuss.elastic.co/t/how-to-send-windows-2012-r2-log-file-to-logstash/28708/6 "2015-09-09T18:26:10Z")

</div>

I have the .exe on a windows server and I am trying to use LSF to ship a log file to my central input LS VM.

Besides having the .exe on the windows machine I want to ship files from, what else do I need?

Do I still need a output config file?  
What do you mean by "invoke?"  
Do you mean launching with cmd or powershell?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [September 9, 2015, 8:04pm UTC](https://discuss.elastic.co/t/how-to-send-windows-2012-r2-log-file-to-logstash/28708/7 "2015-09-09T20:04:24Z")

</div>

> Besides having the .exe on the windows machine I want to ship files from, what else do I need?

You need a configuration file. See the [README file](https://github.com/elastic/logstash-forwarder/blob/master/README.md).

> What do you mean by "invoke?"  
> Do you mean launching with cmd or powershell?

Yes. Invoke, run, start, launch.

---

<div class="post-metadata">

**Author:** ![Kaufusihm](https://avatars.discourse-cdn.com/v4/letter/k/bcef8e/32.png) [@Kaufusihm](https://discuss.elastic.co/u/Kaufusihm)\
**Post date:** [September 9, 2015, 8:06pm UTC](https://discuss.elastic.co/t/how-to-send-windows-2012-r2-log-file-to-logstash/28708/8 "2015-09-09T20:06:03Z")

</div>

What would you suggest to run the LSF .exe? I was just trying to double click it...

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [September 9, 2015, 8:08pm UTC](https://discuss.elastic.co/t/how-to-send-windows-2012-r2-log-file-to-logstash/28708/9 "2015-09-09T20:08:44Z")

</div>

> What would you suggest to run the LSF .exe? I was just trying to double click it...

Please read the documentation. The second line of the [Configuring section](https://github.com/elastic/logstash-forwarder/blob/master/README.md#configuring) shows you to start LSF and a couple of lines down there's a configuration file example.

---

<div class="post-metadata">

**Author:** ![Kaufusihm](https://avatars.discourse-cdn.com/v4/letter/k/bcef8e/32.png) [@Kaufusihm](https://discuss.elastic.co/u/Kaufusihm)\
**Post date:** [September 9, 2015, 8:47pm UTC](https://discuss.elastic.co/t/how-to-send-windows-2012-r2-log-file-to-logstash/28708/10 "2015-09-09T20:47:25Z")

</div>

I believe I have the config file done... There are a few things I know are wrong (ie: the "type" in the files)

I am not surer how to access this config with the .exe...

am I on the right track?

#logstash-forwarder

input {  
lumberjack {  
port =\> 5000  
type =\> "logs"  
ssl\_certificate =\> "/etc/pki/tls/certs/logstash-forwarder.crt"  
ssl\_key =\> "/etc/pki/tls/private/logstash-forwarder.key"  
}  
}

{  
"network": {  
"servers": ["DNS server:5000"]  
"timeout": 15,  
"ssl ca":  
},  
"files": [  
{  
"paths": [  
"user/appprograms/businesslayer.log"  
],  
"fields": { "type": "?" } #I am unsure of what type this is  
}  
]  
}

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [September 9, 2015, 9:13pm UTC](https://discuss.elastic.co/t/how-to-send-windows-2012-r2-log-file-to-logstash/28708/11 "2015-09-09T21:13:55Z")

</div>

It looks like you're mixing Logstash and LSF configurations. The "input" section doesn't belong in an LSF file.

Otherwise it looks fairly reasonable. The type is basically any string that describes what kind of message it is.

Once again, the reader file shows how to start LSF and pass the configuration file path as an argument.

---

<div class="post-metadata">

**Author:** ![Kaufusihm](https://avatars.discourse-cdn.com/v4/letter/k/bcef8e/32.png) [@Kaufusihm](https://discuss.elastic.co/u/Kaufusihm)\
**Post date:** [September 10, 2015, 4:56pm UTC](https://discuss.elastic.co/t/how-to-send-windows-2012-r2-log-file-to-logstash/28708/12 "2015-09-10T16:56:19Z")

</div>

Okay I used the following argument to run LFS via powershell

.\logstash-forwarder\_windows\_386.exe -config .\logstash-forwarder.conf

I'm haivng issues with the SSL certs, which I show in the message below my LSF configuration.

Also, here is my LSF config file but it is having SSL issues.

{  
"network": {  
"servers": ["private\_ip:5000"],  
"timeout": 15,  
"ssl ca": "/etc/pki/tls/certs/logstash-forwarder.crt"  
},  
"files": [  
{  
"paths": [  
"SEUM.BusinessLayer.log" ],  
"fields": { "type": "syslog" }  
}  
]  
}

after I run this I get an error saying:

"  
setting trusted CA from file: /etc/pki/tls/certs/logstash-forwarder.crt  
Failure reading CA certificate: open /etc/pki/tls/certs/logstash-forwarder.crt: The system cannot find the path specified.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [September 10, 2015, 6:52pm UTC](https://discuss.elastic.co/t/how-to-send-windows-2012-r2-log-file-to-logstash/28708/13 "2015-09-10T18:52:50Z")

</div>

The documentation contains an example of how you can create key and certificate files using OpenSSL. You can get that program from the cygwin distribution and there are possibly other Windows ports of OpenSSL. I'm sure there are other native Windows programs for generating X.509 certificates. It's a standardized format.

---

<div class="post-metadata">

**Author:** ![Kaufusihm](https://avatars.discourse-cdn.com/v4/letter/k/bcef8e/32.png) [@Kaufusihm](https://discuss.elastic.co/u/Kaufusihm)\
**Post date:** [September 11, 2015, 5:36pm UTC](https://discuss.elastic.co/t/how-to-send-windows-2012-r2-log-file-to-logstash/28708/14 "2015-09-11T17:36:30Z")

</div>

Magnus,

I have the following LSF config. I am getting a Failed message cause it can't "open /certs/lsfcert.crt: the system cannot find the path specified"

I am not sure how to specify the file path. The LSF.exe and LSF.conf are in the same directory and the the SSL folder is in the same directory as well.

Ideas?

{  
"network": {  
"servers": ["x.x.x.x:xxxx"],  
"timeout": 15,  
"ssl certificate": "/certs/lsfcert.crt",  
"ssl key": "certs/lsfkey.key",  
"ssl ca": "/certs/lsfcert.crt"  
},  
"files": [  
{  
"paths":  
["SEUM.BusinessLayer.log"],  
"fields": { "type": "syslog" }  
}  
]  
}

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [September 11, 2015, 8:06pm UTC](https://discuss.elastic.co/t/how-to-send-windows-2012-r2-log-file-to-logstash/28708/15 "2015-09-11T20:06:33Z")

</div>

Relative paths might work but I'd try an absolute path ("c:/foo/bar/lsfcert.crt") first.

---

<div class="post-metadata">

**Author:** ![Kaufusihm](https://avatars.discourse-cdn.com/v4/letter/k/bcef8e/32.png) [@Kaufusihm](https://discuss.elastic.co/u/Kaufusihm)\
**Post date:** [September 11, 2015, 8:46pm UTC](https://discuss.elastic.co/t/how-to-send-windows-2012-r2-log-file-to-logstash/28708/16 "2015-09-11T20:46:58Z")

</div>

On my central logstash I have the following configs. Am I on the right track?

lsf-input.conf

input {  
lumberjack {  
port =\> 5000  
type =\> "logs"  
ssl\_certificate =\> "/etc/pki/tls/certs/logstash-forwarder.crt"  
ssl\_key =\> "/etc/pki/tls/private/logstash-forwarder.key"  
}  
}

=========================================  
esearch-output.conf

output {  
elasticsearch { host =\> elasticsearch-server:5601 }  
stdout { codec =\> rubydebug }  
}

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [September 12, 2015, 7:04am UTC](https://discuss.elastic.co/t/how-to-send-windows-2012-r2-log-file-to-logstash/28708/17 "2015-09-12T07:04:17Z")

</div>

Yes, except that I don't think you have ES running on port 5601. That's the Kibana port. By default ES's HTTP interface runs on port 9200. However, by default the elasticsearch output doesn't use HTTP so you'd have to specify port 9300. I suggest you just drop the port altogether. As long as you stick to the defaults you don't have to specify it explicitly.

---

<div class="post-metadata">

**Author:** ![Kaufusihm](https://avatars.discourse-cdn.com/v4/letter/k/bcef8e/32.png) [@Kaufusihm](https://discuss.elastic.co/u/Kaufusihm)\
**Post date:** [September 14, 2015, 10:09pm UTC](https://discuss.elastic.co/t/how-to-send-windows-2012-r2-log-file-to-logstash/28708/18 "2015-09-14T22:09:13Z")

</div>

After launching Elasticsearch server, Logstash central, and trying to connect LSF on windows server 2012.

I get the following error on windows shipper:

2015/09/14 16:02:16.444155 Read error looking for ack: WSARecv tcp x.x.x.x  
2015/09/14 16:02:16.445154 Setting trusted CA from file: C:/Users/uxxxxxxx/Des  
2015/09/14 16:02:16.447156 Connecting to [x.x.x.x]:5000 (x.x.x.x.)

Any ideas?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:29am UTC](https://discuss.elastic.co/t/how-to-send-windows-2012-r2-log-file-to-logstash/28708/19 "2017-07-06T05:29:11Z")

</div>


