# Increasing ignore\_older value fails to ship additional events

**URL:** <https://discuss.elastic.co/t/increasing-ignore-older-value-fails-to-ship-additional-events/184898>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [June 9, 2019, 10:04pm UTC](https://discuss.elastic.co/t/increasing-ignore-older-value-fails-to-ship-additional-events/184898 "2019-06-09T22:04:08Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![bharrisonit](https://avatars.discourse-cdn.com/v4/letter/b/7cd45c/32.png) [@bharrisonit](https://discuss.elastic.co/u/bharrisonit)\
**Post date:** [June 9, 2019, 10:04pm UTC](https://discuss.elastic.co/t/increasing-ignore-older-value-fails-to-ship-additional-events/184898/1 "2019-06-09T22:04:08Z")

</div>

Hello!

I assume I'm missing something relatively basic here, but my search has yielded little. I'm using OSS agent version 7.0.1 on WIndows 7.

Following a successful install of winlogbeat which respects the "ignore\_older" value of 72h set for dev purposes, I've increased the value in winlogbeat.yml to a more bulky 336h. My intention is to load the a useful amount of test data from existing hosts, but upon updating the yml file on the target hosts and restarting the service no additional events outside the original 72h period are shipped for indexing.

I suspected that the service might need to be rebuilt following the updates to the config. After updating the winlogbeats.yml file, stopping the winlogbeat service, performing un-installation, a host reboot and installation of the service using the included powershell scripts the host still fails to ship events within the new ignore\_older timeframe.

Is this behavior typical, or am I missing something?

Appreciate any feedback.

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [June 9, 2019, 10:46pm UTC](https://discuss.elastic.co/t/increasing-ignore-older-value-fails-to-ship-additional-events/184898/2 "2019-06-09T22:46:05Z")

</div>

That's the expected behavior. You need to clear the registry file that stores the current read position. That file is located in `C:\ProgramData\winlogbeat\.winlogbeat.yml`. Stop the agent, delete (or modify) the file, then restart the agent.

---

<div class="post-metadata">

**Author:** ![bharrisonit](https://avatars.discourse-cdn.com/v4/letter/b/7cd45c/32.png) [@bharrisonit](https://discuss.elastic.co/u/bharrisonit)\
**Post date:** [June 10, 2019, 12:12am UTC](https://discuss.elastic.co/t/increasing-ignore-older-value-fails-to-ship-additional-events/184898/3 "2019-06-10T00:12:32Z")

</div>

Brilliant; I had found a reference file in a subfolder "data" under the original installation path, but this path wasn't consistent across both dev hosts.

Thanks for the quick response; This worked perfectly.

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [June 10, 2019, 3:47pm UTC](https://discuss.elastic.co/t/increasing-ignore-older-value-fails-to-ship-additional-events/184898/4 "2019-06-10T15:47:28Z")

</div>

When running as a Windows service the file will be written to `C:\ProgramData\winlogbeat\.winlogbeat.yml` because the service sets the `-path.data` flag when starting Winlogbeat. If you start Winlogbeat differently (without -path.data pointing to ProgramData) then it will get written to the CWD.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 8, 2019, 3:47pm UTC](https://discuss.elastic.co/t/increasing-ignore-older-value-fails-to-ship-additional-events/184898/5 "2019-07-08T15:47:33Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
