# Import Saved Windows Event Logs

**URL:** <https://discuss.elastic.co/t/import-saved-windows-event-logs/85302>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [May 10, 2017, 8:28pm UTC](https://discuss.elastic.co/t/import-saved-windows-event-logs/85302 "2017-05-10T20:28:13Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Gregory\_Green](https://avatars.discourse-cdn.com/v4/letter/g/ba8739/32.png) [@Gregory\_Green](https://discuss.elastic.co/u/Gregory_Green)\
**Post date:** [May 10, 2017, 8:28pm UTC](https://discuss.elastic.co/t/import-saved-windows-event-logs/85302/1 "2017-05-10T20:28:13Z")

</div>

Hello,

I have .evtx logs saved to CD/DVDs that I would like elasticsearch to ingest. Is there a way to change the path that winlogbeat uses to check for logs? I've tried converting them to .csv files and utilizing filebeat to send to elasticsearch, which works (sort of). But not all of the fields are parsed. I'd rather not have to write a template for this. Help? Thanks in advance.

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [May 10, 2017, 10:08pm UTC](https://discuss.elastic.co/t/import-saved-windows-event-logs/85302/2 "2017-05-10T22:08:09Z")

</div>

It's not possible to use Winlogbeat for this. Though it would be great feature.

> [@Winlogbeat - how to change path for where to look for files](https://discuss.elastic.co/t/winlogbeat-how-to-change-path-for-where-to-look-for-files/64492):
>
> Does any one know what configuration if any I can put in the YAML file to specify a location for where my windows event logs reside. I have a folder with archived data that i need winlogbeat to index into elasticsearch... anyone know?

> [@Winlogbeat: Logstash as forensic investigator](https://discuss.elastic.co/t/winlogbeat-logstash-as-forensic-investigator/67612):
>
> Hi I am trying to parse log files collected as part of forensic investigation from windows machine and wondering how can i make winlogbeat to parse logs from files and ship it to logstash server? Do we have a winlogbeat for linux as well so that i can run winlogbeat on my linux machine to ship logs to logstash or if there is any other way to read these files? Regards TS

---

<div class="post-metadata">

**Author:** ![Gregory\_Green](https://avatars.discourse-cdn.com/v4/letter/g/ba8739/32.png) [@Gregory\_Green](https://discuss.elastic.co/u/Gregory_Green)\
**Post date:** [May 10, 2017, 10:12pm UTC](https://discuss.elastic.co/t/import-saved-windows-event-logs/85302/3 "2017-05-10T22:12:36Z")

</div>

Thanks for the info. Are you aware of any documentation related to accomplishing this via filebeat ?

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [May 10, 2017, 10:46pm UTC](https://discuss.elastic.co/t/import-saved-windows-event-logs/85302/4 "2017-05-10T22:46:19Z")

</div>

No, there's nothing in Filebeat for this either.

If you wanted to do some Go development I can potentially see a path that reuses the Winlogbeat code. You could export the records from the .evtx file to XML using the tools in windows. Then write a custom processor (similar to the [decode\_json\_fields](https://www.elastic.co/guide/en/beats/filebeat/master/decode-json-fields.html) processor ([source](https://github.com/elastic/beats/blob/master/libbeat/processors/actions/decode_json_fields.go)) that uses the [Winlogbeat code](https://github.com/elastic/beats/blob/master/winlogbeat/eventlog/wineventlog.go#L200-L203) to parse the XML. Then read the XML log lines using Filebeat and enable your custom eventlog xml processor. The config might look something like:

```auto
filebeat.prospectors:
  - paths: ['eventlog.xml']
processors:
- decode_eventlog_xml: {}
output.elasticsearch.hosts: ["http://localhost:9200"]

```

---

<div class="post-metadata">

**Author:** ![Gregory\_Green](https://avatars.discourse-cdn.com/v4/letter/g/ba8739/32.png) [@Gregory\_Green](https://discuss.elastic.co/u/Gregory_Green)\
**Post date:** [May 16, 2017, 9:47pm UTC](https://discuss.elastic.co/t/import-saved-windows-event-logs/85302/5 "2017-05-16T21:47:30Z")

</div>

A solutions engineer provided me with the following:

1. file.output --\> Elasticsearch  
After installing Winlogbeat on the machines producing the logs contained on my CD/DVDs ...  
...Using this approach, you would be able to pull JSON-formatted. logs from isolated machines, move them to a machine with connectivity to ES, and the use Filebeat or Logstash to read those logs and push them to ES.  
[https://www.elastic.co/guide/en/beats/winlogbeat/current/file-output.html](https://www.elastic.co/guide/en/beats/winlogbeat/current/file-output.html)

If installing Winlogbeat is not possible, then there are a couple of options, all of which involve converting the .evtx files into something else:

1. Custom parser --\> ES  
You could write a custom parser that would use a third party lib to read the .evtx files, build the necessary json and post to ES over the HTTP API. I'd recommend utilizing the '\_bulk' endpoint.  
[https://www.elastic.co/guide/en/elasticsearch/reference/current/docs-bulk.html](https://www.elastic.co/guide/en/elasticsearch/reference/current/docs-bulk.html)  
[https://github.com/plutonbacon/evtx.rb](https://github.com/plutonbacon/evtx.rb)  
[https://github.com/williballenthin/python-evtx](https://github.com/williballenthin/python-evtx)

2. Apache NiFi --\> ES  
NiFi has built-in support for .evtx files. You can use it to build a pipeline that takes the .evtx logs from the filesystem, parses out the data, builds the necessary json, and posts it to Elasticsearch.  
[https://www.community.hortonworks.com/articles/58493/parsing-evtx-files-with-apache-nifi.html](https://www.community.hortonworks.com/articles/58493/parsing-evtx-files-with-apache-nifi.html)

Logstash may play a useful role in any of these scenarios.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 31, 2017, 8:30pm UTC](https://discuss.elastic.co/t/import-saved-windows-event-logs/85302/6 "2017-05-31T20:30:21Z")

</div>

This topic was automatically closed after 21 days. New replies are no longer allowed.
