# Logstash lost eventlog from winlogbeat

**URL:** <https://discuss.elastic.co/t/logstash-lost-eventlog-from-winlogbeat/55360>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [July 13, 2016, 1:01am UTC](https://discuss.elastic.co/t/logstash-lost-eventlog-from-winlogbeat/55360 "2016-07-13T01:01:06Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![orsa](https://avatars.discourse-cdn.com/v4/letter/o/5daacb/32.png) [@orsa](https://discuss.elastic.co/u/orsa)\
**Post date:** [July 13, 2016, 1:01am UTC](https://discuss.elastic.co/t/logstash-lost-eventlog-from-winlogbeat/55360/1 "2016-07-13T01:01:06Z")

</div>

Hi  
i dont undestend where i wrong (.  
on my server (Ubuntu) install ELK  
logstash recive syslog and netflow messages from network devices - all work all right.  
Install on some windows server Winlogbeat  
use send log to elasticsearch direct - all work right  
use send log to logstash - event can not send to ES  
errors from LS - none.

LS config

```auto
    input {
            # netflow v9
            udp {
                    type => "mtnfv9"
                    port => 9995
                    codec => netflow {
                    versions => [9]
                    }

            }
            #tcp syslog stream via 5140
            tcp {
                    type => "mtsl"
                    port => 5141

                    }

            #udp syslogs tream via 5140
            udp {
                    type => "mtsl"
                    port => 5141
 
                    }
            # windows eventlog from winlogbeats
            beats {
                    type => msel
                    port => 5044
            }
    }
    filter {

            if [type] == "mtnfv9" { some filters}
    else if [type] == "msel" {none filters}
    else if [type] == "mtsl" {some filters}

    }

    output {
                      elasticsearch {
                            hosts => ["192.168.1.42"]
                            manage_template => false
                            index => "%{[@metadata][type]}-%{+YYYY.MM.dd}"
                            document_type => "%{[@metadata][type]}"
                           }   
    }

```

see packet thow tcpdump - packet sent and recive  
plugin - logstash-input-beats - installed

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [July 13, 2016, 1:38am UTC](https://discuss.elastic.co/t/logstash-lost-eventlog-from-winlogbeat/55360/2 "2016-07-13T01:38:18Z")

</div>

Setting the `type => msel` on the beats input will not take effect because [`type`](https://www.elastic.co/guide/en/beats/winlogbeat/current/exported-fields-common.html#_type) is already set in the event sent by winlogbeat. See the beats input documentation [here](https://www.elastic.co/guide/en/logstash/current/plugins-inputs-beats.html#plugins-inputs-beats-type).

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [July 13, 2016, 1:59am UTC](https://discuss.elastic.co/t/logstash-lost-eventlog-from-winlogbeat/55360/3 "2016-07-13T01:59:18Z")

</div>

Try using the following output so you can see the full event from Winlogbeat then adjust your filters appropriately.

`stdout { codec => rubydebug { metadata => true } }`

---

<div class="post-metadata">

**Author:** ![orsa](https://avatars.discourse-cdn.com/v4/letter/o/5daacb/32.png) [@orsa](https://discuss.elastic.co/u/orsa)\
**Post date:** [July 13, 2016, 10:03am UTC](https://discuss.elastic.co/t/logstash-lost-eventlog-from-winlogbeat/55360/4 "2016-07-13T10:03:00Z")

</div>

HI andrewkroh,  
thank for your reply  
i did it your recomendation.  
no effekt (

```
input {
        beats {
                port => 5044
        }
}

output {
        stdout { codec => rubydebug }
        elasticsearch {
                hosts => ["192.168.1.42"]
                manage_template => false
                index => "%{[@metadata][type]}-%{+YYYY.MM.dd}"
                document_type => "%{[@metadata][type]}"
        }
}

```

root@it-logmon01:~# /opt/logstash/bin/logstash-plugin list | grep "beats"  
logstash-input-beats

---

<div class="post-metadata">

**Author:** ![orsa](https://avatars.discourse-cdn.com/v4/letter/o/5daacb/32.png) [@orsa](https://discuss.elastic.co/u/orsa)\
**Post date:** [July 13, 2016, 10:44am UTC](https://discuss.elastic.co/t/logstash-lost-eventlog-from-winlogbeat/55360/5 "2016-07-13T10:44:07Z")

</div>

New information  
error

`Beats input: unhandled exception {:exception=>#<SystemCallError: Unknown error - No message available>, :backtrace=>["org/jrub y/RubyIO.java:3020:in`sysread'", "/opt/logstash/vendor/bundle/jruby/1.9/gems/logstash-input-beats-2.2.9/lib/lumberjack/beats/ server.rb:463:in `read_socket'", "/opt/logstash/vendor/bundle/jruby/1.9/gems/logstash-input-beats-2.2.9/lib/lumberjack/beats/s erver.rb:443:in`run'", "/opt/logstash/vendor/bundle/jruby/1.9/gems/logstash-input-beats-2.2.9/lib/logstash/inputs/beats\_suppo rt/connection\_handler.rb:34:in `accept'", "/opt/logstash/vendor/bundle/jruby/1.9/gems/logstash-input-beats-2.2.9/lib/logstash/ inputs/beats.rb:211:in`handle\_new\_connection'", "/opt/logstash/vendor/bundle/jruby/1.9/gems/logstash-input-beats-2.2.9/lib/lo gstash/inputs/beats\_support/circuit\_breaker.rb:42:in `execute'", "/opt/logstash/vendor/bundle/jruby/1.9/gems/logstash-input-be ats-2.2.9/lib/logstash/inputs/beats.rb:211:in`handle\_new\_connection'", "/opt/logstash/vendor/bundle/jruby/1.9/gems/logstash-i nput-beats-2.2.9/lib/logstash/inputs/beats.rb:167:in `run'"], :level=>:error}`

may be i most manual update it plugin from gem?

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [July 13, 2016, 2:47pm UTC](https://discuss.elastic.co/t/logstash-lost-eventlog-from-winlogbeat/55360/6 "2016-07-13T14:47:38Z")

</div>

> [@orsa](#):
>
> may be i most manual update it plugin from gem?

You could try updating the plugin with [these commands](https://www.elastic.co/guide/en/logstash/current/working-with-plugins.html#updating-plugins).

---

<div class="post-metadata">

**Author:** ![orsa](https://avatars.discourse-cdn.com/v4/letter/o/5daacb/32.png) [@orsa](https://discuss.elastic.co/u/orsa)\
**Post date:** [July 13, 2016, 3:19pm UTC](https://discuss.elastic.co/t/logstash-lost-eventlog-from-winlogbeat/55360/7 "2016-07-13T15:19:41Z")

</div>

Andrey thank for your reply.  
then i run update plugins - process freeze (

```
/opt/logstash# ./bin/logstash-plugin update logstash-input-beats
You are updating logstash-input-beats to a new version 3.0.3, which may not be compatible with 2.2.9. are you sure you want to proceed (Y/N)?
Y
Updating logstash-input-beats

```

i most update plugin for it corect work?

---

<div class="post-metadata">

**Author:** ![orsa](https://avatars.discourse-cdn.com/v4/letter/o/5daacb/32.png) [@orsa](https://discuss.elastic.co/u/orsa)\
**Post date:** [July 14, 2016, 2:52pm UTC](https://discuss.elastic.co/t/logstash-lost-eventlog-from-winlogbeat/55360/8 "2016-07-14T14:52:09Z")

</div>

anybody help me with my problem?  
any idea?

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [July 14, 2016, 3:04pm UTC](https://discuss.elastic.co/t/logstash-lost-eventlog-from-winlogbeat/55360/9 "2016-07-14T15:04:12Z")

</div>

Based on that warning, I'd say the version is incompatible and my suggestion of making sure you have the latest plugin version wasn't so good. I'd revert to a clean Logstash install.

You'll probably get better responses regarding the Logstash exception you encountered if you post in the Logstash category. Include your OS, Logstash version, config, and the exception when you post.

---

<div class="post-metadata">

**Author:** ![orsa](https://avatars.discourse-cdn.com/v4/letter/o/5daacb/32.png) [@orsa](https://discuss.elastic.co/u/orsa)\
**Post date:** [July 14, 2016, 3:17pm UTC](https://discuss.elastic.co/t/logstash-lost-eventlog-from-winlogbeat/55360/10 "2016-07-14T15:17:43Z")

</div>

Andrey thank you  
at this time i write message in logstash category )

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 4, 2016, 3:17pm UTC](https://discuss.elastic.co/t/logstash-lost-eventlog-from-winlogbeat/55360/11 "2016-08-04T15:17:55Z")

</div>

This topic was automatically closed 21 days after the last reply. New replies are no longer allowed.
