# Howto config winlogbeat + logstash + elasticsearch?

**URL:** <https://discuss.elastic.co/t/howto-config-winlogbeat-logstash-elasticsearch/374393>\
**Category:** Logstash\
**Created:** [February 12, 2025, 2:05am UTC](https://discuss.elastic.co/t/howto-config-winlogbeat-logstash-elasticsearch/374393 "2025-02-12T02:05:16Z")\
**Posts on this page:** 14\
**Page:** 1

<div class="post-metadata">

**Author:** ![Lynn\_Karllo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lynn_karllo/32/141304_2.png) [@Lynn\_Karllo](https://discuss.elastic.co/u/Lynn_Karllo)\
**Post date:** [February 12, 2025, 2:05am UTC](https://discuss.elastic.co/t/howto-config-winlogbeat-logstash-elasticsearch/374393/1 "2025-02-12T02:05:16Z")

</div>

```auto
Config winlogbeat:
winlogbeat.event_logs:
  - name: Application
    ignore_older: 72h
  - name: System
  - name: Security
  - name: Microsoft-Windows-Sysmon/Operational
  - name: Windows PowerShell
    event_id: 400, 403, 600, 800
  - name: Microsoft-Windows-PowerShell/Operational
    event_id: 4103, 4104, 4105, 4106
  - name: ForwardedEvents
    tags: [forwarded]
setup.template.settings:
  index.number_of_shards: 1
output.logstash:
  hosts: ["IP_EXAMPLE:3333"]
  ssl.certificate_authorities: ["C:/Program Files/winlogbeat/ca_logstash_cert.pem"]
  ssl.certificate: "C:/Program Files/winlogbeat/logstash_server.crt"
  ssl.key: "C:/Program Files/winlogbeat/logstash_server.key"
  verification_mode: certificate
processors:
  - add_host_metadata:
      when.not.contains.tags: forwarded
  - add_cloud_metadata: ~
  -
Config logstash: 

input {
  beats {
    port => 3333
    ssl_enabled => true
    ssl_certificate_authorities => "/etc/logstash/certs/ca_logstash_cert.pem"
    ssl_certificate => "/etc/logstash/certs/logstash_server.crt"
    ssl_key => "/etc/logstash/certs/logstash_server.key"
    ssl_client_authentication => "required"
    type => winlogbeat
  }
}
filter {
if [type] == "winlogbeat"{
    mutate { add_field => { "[@metadata][pipeline]" => "winlogbeat-%{[agent][version]}-routing" } }
  } else if !([@metadata][pipeline]) {
    mutate { add_field => { "[@metadata][pipeline]" => "" } }
}
}  
output {
  elasticsearch {
    ssl_enabled => true
    hosts => ["https://localhost:9200"]
    ssl_verification_mode => none
    ssl_certificate_authorities => "/etc/pki/tls/certs/ca_authorities.crt"
    api_key => "adfadfadfdafadfadkjj323i4uiu4" 
    data_stream => auto
    index => "%{[@metadata][beat]}-%{[@metadata][version]}-%{+YYYY.MM.dd}"
    document_type => "%{[@metadata][type]}"
    action => "create"
  } 	  
}

```

This configuration not work. why ? which problem?  
I imported template and dashboard winlogbeat.  
I am use winlogbeat 8.17.1, logstash 8.17.1 and elasticsearch 8.17.1.  
The dashboard becomes empty.  
The template does not recognize logs winlogbeat.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 12, 2025, 2:08am UTC](https://discuss.elastic.co/t/howto-config-winlogbeat-logstash-elasticsearch/374393/2 "2025-02-12T02:08:07Z")

</div>

> [@Lynn\_Karllo](#):
>
> This configuration not work. why ?

What errors do you get? What do you see in the winlogbeat and logstash logs?

---

<div class="post-metadata">

**Author:** ![Lynn\_Karllo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lynn_karllo/32/141304_2.png) [@Lynn\_Karllo](https://discuss.elastic.co/u/Lynn_Karllo)\
**Post date:** [February 12, 2025, 2:21am UTC](https://discuss.elastic.co/t/howto-config-winlogbeat-logstash-elasticsearch/374393/3 "2025-02-12T02:21:59Z")

</div>

![Screenshot From 2025-02-11 23-17-43](https://us1.discourse-cdn.com/elastic/original/3X/d/d/dd16da766f42bdb26285ece46bef3adbe6e96cec.png)

---

<div class="post-metadata">

**Author:** ![Lynn\_Karllo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lynn_karllo/32/141304_2.png) [@Lynn\_Karllo](https://discuss.elastic.co/u/Lynn_Karllo)\
**Post date:** [February 12, 2025, 2:31am UTC](https://discuss.elastic.co/t/howto-config-winlogbeat-logstash-elasticsearch/374393/4 "2025-02-12T02:31:02Z")

</div>

It is not recognizing some tags.  
Example:  
related.user  
user.domain  
user.id  
user.name

 ![Screenshot From 2025-02-11 23-26-25](https://us1.discourse-cdn.com/elastic/original/3X/b/5/b5f4c29ebfe55a4ff976085c0587e7868b1409aa.png)

---

<div class="post-metadata">

**Author:** ![Lynn\_Karllo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lynn_karllo/32/141304_2.png) [@Lynn\_Karllo](https://discuss.elastic.co/u/Lynn_Karllo)\
**Post date:** [February 12, 2025, 2:31am UTC](https://discuss.elastic.co/t/howto-config-winlogbeat-logstash-elasticsearch/374393/5 "2025-02-12T02:31:52Z")

</div>

When i configuration winlogbeat with elasticsearch. The tags work.

 ![Screenshot From 2025-02-11 23-29-48](https://us1.discourse-cdn.com/elastic/original/3X/b/d/bd517c5a9eb72f5efe5193a0d4e1d3de1346dd3c.png)

---

<div class="post-metadata">

**Author:** ![Lynn\_Karllo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lynn_karllo/32/141304_2.png) [@Lynn\_Karllo](https://discuss.elastic.co/u/Lynn_Karllo)\
**Post date:** [February 12, 2025, 2:34am UTC](https://discuss.elastic.co/t/howto-config-winlogbeat-logstash-elasticsearch/374393/6 "2025-02-12T02:34:50Z")

</div>

![Screenshot From 2025-02-11 23-34-20](https://us1.discourse-cdn.com/elastic/original/3X/e/4/e4ecc817fd548c565194ef7080a72954f71ebea3.png)

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [February 12, 2025, 2:35am UTC](https://discuss.elastic.co/t/howto-config-winlogbeat-logstash-elasticsearch/374393/7 "2025-02-12T02:35:07Z")

</div>

> [@Lynn\_Karllo](#):
>
> When i configuration winlogbeat with elasticsearch. The tags work.

What is the index name when you send it directly to Elasticsearch?

The beats on version 8 creates data stream, and data streams have a different naming schema.

This is not correct:

```auto
index => "%{[@metadata][beat]}-%{[@metadata][version]}-%{+YYYY.MM.dd}"

```

It should be just as the example in the [documentation](https://www.elastic.co/guide/en/beats/winlogbeat/current/logstash-output.html#_accessing_metadata_fields)

```auto
index => "%{[@metadata][beat]}-%{[@metadata][version]}"

```

---

<div class="post-metadata">

**Author:** ![Lynn\_Karllo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lynn_karllo/32/141304_2.png) [@Lynn\_Karllo](https://discuss.elastic.co/u/Lynn_Karllo)\
**Post date:** [February 12, 2025, 2:51am UTC](https://discuss.elastic.co/t/howto-config-winlogbeat-logstash-elasticsearch/374393/8 "2025-02-12T02:51:36Z")

</div>

Same problem. I tested.  
I think this is the problem.  
Tags: beats\_input\_codec\_plain\_applied and  
\_ignored:[event.original.keyword, message.keyword]

---

<div class="post-metadata">

**Author:** ![Lynn\_Karllo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lynn_karllo/32/141304_2.png) [@Lynn\_Karllo](https://discuss.elastic.co/u/Lynn_Karllo)\
**Post date:** [February 12, 2025, 2:57am UTC](https://discuss.elastic.co/t/howto-config-winlogbeat-logstash-elasticsearch/374393/9 "2025-02-12T02:57:01Z")

</div>

When i use winlogbeat with elasticsearch i don't see "beats\_input\_codec\_plain\_applied" and "\_ignored:[event.original.keyword, message.keyword]".

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [February 12, 2025, 4:17am UTC](https://discuss.elastic.co/t/howto-config-winlogbeat-logstash-elasticsearch/374393/10 "2025-02-12T04:17:14Z")

</div>

> [@Lynn\_Karllo](#):
>
> When i use winlogbeat with elasticsearch i don't see "beats\_input\_codec\_plain\_applied" and "\_ignored:[event.original.keyword, message.keyword]".

What is the name of the index when you send directly to Elasticsearch? You didn't share it.

Please provide more context to make it clear to where winlogbeat is writing the events when using Logstash and when using Elasticsearch.

Also, You need to change your pipeline to something like the one in the [documentation](https://www.elastic.co/guide/en/logstash/current/winlogbeat-modules.html#use-winlogbeat-ingest-pipelines).

Your logstash output does not have information about which pipeline the request should use when arriving into Elasticsearch, you need to have a `pipeline` setting in your logstash output as described in the documentation, without it your message will note be fully parsed and some fields will be missing.

Remove your `filter` block, your output should be something like this:

```auto
output {
  if [@metadata][pipeline] {
    elasticsearch {
      hosts => ["https://localhost:9200"]
      ssl_enabled => true
      ssl_verification_mode => none
      ssl_certificate_authorities => "/etc/pki/tls/certs/ca_authorities.crt"
      api_key => "adfadfadfdafadfadkjj323i4uiu4" 
      manage_template => false
      index => "%{[@metadata][beat]}-%{[@metadata][version]}" 
      action => "create" 
      pipeline => "%{[@metadata][pipeline]}" 
    }
  } else {
    elasticsearch {
      hosts => ["https://localhost:9200"]
      ssl_enabled => true
      ssl_verification_mode => none
      ssl_certificate_authorities => "/etc/pki/tls/certs/ca_authorities.crt"
      api_key => "adfadfadfdafadfadkjj323i4uiu4" 
      manage_template => false
      index => "%{[@metadata][beat]}-%{[@metadata][version]}" 
      action => "create" 
    }
  }
}

```

---

<div class="post-metadata">

**Author:** ![Lynn\_Karllo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lynn_karllo/32/141304_2.png) [@Lynn\_Karllo](https://discuss.elastic.co/u/Lynn_Karllo)\
**Post date:** [February 13, 2025, 2:40am UTC](https://discuss.elastic.co/t/howto-config-winlogbeat-logstash-elasticsearch/374393/11 "2025-02-13T02:40:21Z")

</div>

Now it's working.

```auto
input {
  beats {
    port => 5044
    ssl_enabled => true
    ssl_certificate_authorities => "/etc/logstash/certs/ca_logstash_cert.pem"
    ssl_certificate => "/etc/logstash/certs/logstash_server.crt"
    ssl_key => "/etc/logstash/certs/logstash_server.key"
    ssl_client_authentication => "required"
    enrich => none
  }
}
output {
    elasticsearch {
      hosts => ["https://localhost:9200"]
      ssl_enabled => true
      ssl_verification_mode => none
      ssl_certificate_authorities => "/etc/pki/tls/certs/ca_authorities.crt"
      api_key => "adfadfadfdafadfadkjj323i4uiu4" 
      data_stream => false
      manage_template => false
      index => "%{[@metadata][beat]}-%{[@metadata][version]}" 
      pipeline => "%{[@metadata][beat]}-%{[@metadata][version]}-routing"
      action => "create" 
    }
}

```

---

<div class="post-metadata">

**Author:** ![Lynn\_Karllo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lynn_karllo/32/141304_2.png) [@Lynn\_Karllo](https://discuss.elastic.co/u/Lynn_Karllo)\
**Post date:** [February 13, 2025, 2:43am UTC](https://discuss.elastic.co/t/howto-config-winlogbeat-logstash-elasticsearch/374393/12 "2025-02-13T02:43:32Z")

</div>

Thank you so much. I will study more about pipeline.

---

<div class="post-metadata">

**Author:** ![rugenl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rugenl/32/12887_2.png) [@rugenl](https://discuss.elastic.co/u/rugenl)\
**Post date:** [February 13, 2025, 3:01am UTC](https://discuss.elastic.co/t/howto-config-winlogbeat-logstash-elasticsearch/374393/13 "2025-02-13T03:01:01Z")

</div>

Elastic agent sending direct to Elastic is the more modern method. Then use System, Windows and any other integrations as needed.

---

<div class="post-metadata">

**Author:** ![Lynn\_Karllo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lynn_karllo/32/141304_2.png) [@Lynn\_Karllo](https://discuss.elastic.co/u/Lynn_Karllo)\
**Post date:** [February 14, 2025, 12:26am UTC](https://discuss.elastic.co/t/howto-config-winlogbeat-logstash-elasticsearch/374393/14 "2025-02-14T00:26:10Z")

</div>

Exact Rugenl, but i need send log to syslog and elasticsearch. Winlogbeat don´t do this. 🙂
