# Logstash Input Eventlog

**URL:** <https://discuss.elastic.co/t/logstash-input-eventlog/66364>\
**Category:** Logstash\
**Created:** [November 17, 2016, 10:37am UTC](https://discuss.elastic.co/t/logstash-input-eventlog/66364 "2016-11-17T10:37:23Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![RdrgPorto](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rdrgporto/32/13278_2.png) [@RdrgPorto](https://discuss.elastic.co/u/RdrgPorto)\
**Post date:** [November 17, 2016, 10:37am UTC](https://discuss.elastic.co/t/logstash-input-eventlog/66364/1 "2016-11-17T10:37:23Z")

</div>

Hi everyone,

I have a trouble with **Input Eventlog** with **Logstash 2.3.4** in **Windows 2008 R2**. My configuration:

> input {  
> eventlog {  
> type =\> "test"  
> logfile =\> "Test Application Log"  
> }  
> }

I am trying to obtain **Test Application Log** under **Applications and Services Logs**. I type the logfile name literally as it appears in **Event Viewer**. However, I receice this error:

> "Invalid setting for eventlog input plugin:\n\n input {\n eventlog {\n # This setting must be a ["Application", "Security", "System"]\n # Expected one of ["Application", "Security", "System"], got ["Test Application Log"]\n logfile =\> ["Test Application Log"]\n ...\n }\n }", :level=\>:error}

Thanks in advance,

Regards

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [November 17, 2016, 10:41am UTC](https://discuss.elastic.co/t/logstash-input-eventlog/66364/2 "2016-11-17T10:41:37Z")

</div>

Any reason you are not using [Winlogbeat](https://www.elastic.co/products/beats/winlogbeat), which according to the [support matrix](https://www.elastic.co/support/matrix) is supported on that platform?

---

<div class="post-metadata">

**Author:** ![RdrgPorto](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rdrgporto/32/13278_2.png) [@RdrgPorto](https://discuss.elastic.co/u/RdrgPorto)\
**Post date:** [November 17, 2016, 10:46am UTC](https://discuss.elastic.co/t/logstash-input-eventlog/66364/3 "2016-11-17T10:46:35Z")

</div>

Hi Christian,

I know about **Winlogbeat** , however I prefer to user **Input Eventlog**.

Is there any problem with **Eventlog**? How should I use it?

Thanks in advance

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [November 17, 2016, 10:56am UTC](https://discuss.elastic.co/t/logstash-input-eventlog/66364/4 "2016-11-17T10:56:06Z")

</div>

I do not run Windows, so have no personal preference or experience. The event log plugin is a community supported plugin while Winlogbeat is a core Elastic component under active development. Based on this I would suspect that you might be able to get more support on Winlogbeat than the event log plugin.

---

<div class="post-metadata">

**Author:** ![RdrgPorto](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rdrgporto/32/13278_2.png) [@RdrgPorto](https://discuss.elastic.co/u/RdrgPorto)\
**Post date:** [November 18, 2016, 7:29am UTC](https://discuss.elastic.co/t/logstash-input-eventlog/66364/5 "2016-11-18T07:29:06Z")

</div>

Hi,

I have seen in **Github** an issue that is about this problem: [Issue](https://github.com/logstash-plugins/logstash-input-eventlog/issues/31).

Regarding to **Winlogbeat** , I would like to have the option " **congestion\_threshold**" in order to have a good control about Redis.

Regards

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [November 18, 2016, 7:47am UTC](https://discuss.elastic.co/t/logstash-input-eventlog/66364/6 "2016-11-18T07:47:28Z")

</div>

That sounds like a useful feature request. Please feel free to open an enhancement request against the [libbeat GitHub repository](https://github.com/elastic/libbeat), as this is the component that handles the integration with Redis.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 16, 2016, 7:47am UTC](https://discuss.elastic.co/t/logstash-input-eventlog/66364/7 "2016-12-16T07:47:47Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
