# Logstash event log windows question mark issue

**URL:** <https://discuss.elastic.co/t/logstash-event-log-windows-question-mark-issue/119031>\
**Category:** Logstash\
**Created:** [February 8, 2018, 11:52am UTC](https://discuss.elastic.co/t/logstash-event-log-windows-question-mark-issue/119031 "2018-02-08T11:52:29Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![miki\_haiat](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/miki_haiat/32/83361_2.png) [@miki\_haiat](https://discuss.elastic.co/u/miki_haiat)\
**Post date:** [February 8, 2018, 11:52am UTC](https://discuss.elastic.co/t/logstash-event-log-windows-question-mark-issue/119031/1 "2018-02-08T11:52:29Z")

</div>

Hi im trying to read the event log with the event log plugin .  
Unfortunately all the incoming text is written with question mark

I tried various of charset but it was the same

this is the conf file

> input {  
> eventlog {  
> codec =\> plain { charset =\> "UTF-16" }  
> logfile =\> 'Security'  
> }  
> }  
> output {  
> stdout { codec =\> json }  
> }

and this is the output

> [2018-02-08T12:01:27,837][INFO][logstash.agent] Pipelines running {:count=\>1, :pipelines=\>["main"]}  
> {"RecordNumber":79924266,"host":"M2044653-W10","EventType":"???????","@version":"1","@timestamp":"2018-02-08T10:01:49.182Z","Type":"???????","message":"??????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????","SourceName":"??????????????????","TimeGenerated":"2018-02-08T10:01:23.000Z","InsertionStrings":["????","???????","???","???","??","???","???????????????????"],"ComputerName":"????????????","Logfile":"Security","User":null,"EventIdentifier":4689,"Category":13313,"TimeWritten":"2018-02-08T10:01:23.000Z"}{"RecordNumber":79924267,"host":"M2044653-W10","EventType":"???????","@version":"1","@timestamp":"2018-02-08T10:01:49.213Z","Type":"???????","message":"??????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????","SourceName":"??????????????????","TimeGenerated":"2018-02-08T10:01:47.000Z","InsertionStrings":["????","???????","???","???","???","????????????????","???","??","","????","?","?","??","????????????????","??????"],"ComputerName":"????????????","Logfile":"Security","User":null,"EventIdentifier":4688,"Category":13312,"TimeWritten":"2018-02-08T10:01:47.000Z"}[2018-02-08T12:01:52,959][WARN][logstash.runner] SIGINT received. Shutting down.  
> [2018-02-08T12:01:53,499][INFO][logstash.pipeline] Pipeline has terminated {:pipeline\_id=\>"main", :thread=\>"#\<Thread:0x6e27f6a0 run\>"}

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 8, 2018, 11:52am UTC](https://discuss.elastic.co/t/logstash-event-log-windows-question-mark-issue/119031/2 "2018-03-08T11:52:52Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
