# Import Saved Windows Event Logs

**URL:** <https://discuss.elastic.co/t/import-saved-windows-event-logs/85302>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [May 10, 2017, 8:28pm UTC](https://discuss.elastic.co/t/import-saved-windows-event-logs/85302 "2017-05-10T20:28:13Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [May 10, 2017, 10:08pm UTC](https://discuss.elastic.co/t/import-saved-windows-event-logs/85302/2 "2017-05-10T22:08:09Z")

</div>

It's not possible to use Winlogbeat for this. Though it would be great feature.

> [@Winlogbeat - how to change path for where to look for files](https://discuss.elastic.co/t/winlogbeat-how-to-change-path-for-where-to-look-for-files/64492):
>
> Does any one know what configuration if any I can put in the YAML file to specify a location for where my windows event logs reside. I have a folder with archived data that i need winlogbeat to index into elasticsearch... anyone know?

> [@Winlogbeat: Logstash as forensic investigator](https://discuss.elastic.co/t/winlogbeat-logstash-as-forensic-investigator/67612):
>
> Hi I am trying to parse log files collected as part of forensic investigation from windows machine and wondering how can i make winlogbeat to parse logs from files and ship it to logstash server? Do we have a winlogbeat for linux as well so that i can run winlogbeat on my linux machine to ship logs to logstash or if there is any other way to read these files? Regards TS

---

_[View the full topic](https://discuss.elastic.co/t/import-saved-windows-event-logs/85302)._
