# Logstash vs winlogbeats from external machine

**URL:** <https://discuss.elastic.co/t/logstash-vs-winlogbeats-from-external-machine/86102>\
**Category:** Logstash\
**Created:** [May 17, 2017, 12:35pm UTC](https://discuss.elastic.co/t/logstash-vs-winlogbeats-from-external-machine/86102 "2017-05-17T12:35:33Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![ssi](https://avatars.discourse-cdn.com/v4/letter/s/a3d4f5/32.png) [@ssi](https://discuss.elastic.co/u/ssi)\
**Post date:** [May 17, 2017, 12:35pm UTC](https://discuss.elastic.co/t/logstash-vs-winlogbeats-from-external-machine/86102/1 "2017-05-17T12:35:33Z")

</div>

I've been throught the posts aut have yet to find a solution.

i've opend port 5044 on firewall on both sending client and receving server. I can telnet on port 5044 to the logstash server on the 5044 port.

but i get this in the winbeatlog file

**remote machine winlogbeat file:**

17T12:16:16.1829183Z","uptime":"1m30.0542879s","uptime\_ms":"90054287"}  
2017-05-17T14:18:16+02:00 INFO Non-zero metrics in the last 30s: uptime={"server\_time":"2017-05-17T12:18:16.2376954Z","start\_time":"2017-05-17T12:16:16.1829183Z","uptime":"2m0.0547771s","uptime\_ms":"120054777"}

* * *

_2017-05-17T14:18:27+02:00 ERR Failed to publish events caused by: write tcp 172.16.128.11:11937-\>172.17.20.201:5044: wsasend: An existing connection was forcibly closed by the remote host._  
_2017-05-17T14:18:27+02:00 INFO Error publishing events (retrying): write tcp 172.16.128.11:11937-\>172.17.20.201:5044: wsasend: An existing connection was forcibly closed by the remote host._

* * *

2017-05-17T14:18:28+02:00 INFO EventLog[Microsoft-Windows-Sysmon/Operational] Successfully published 1 events  
2017-05-17T14:18:29+02:00 INFO EventLog[Microsoft-Windows-Sysmon/Operational] Successfully published 1 events  
2017-05-17T14:18:46+02:00 INFO Non-zero metrics in the last 30s: libbeat.logstash.call\_count.PublishEvents=3 libbeat.logstash.publish.read\_bytes=12 libbeat.logstash.publish.write\_bytes=1974 libbeat.logstash.publish.write\_errors=1 libbeat.logstash.published\_and\_acked\_events=2 libbeat.logstash.published\_but\_not\_acked\_events=1 libbeat.publisher.published\_events=2 msg\_file\_cache.Microsoft-Windows-Sysmon/OperationalHits=2 published\_events.Microsoft-Windows-Sysmon/Operational=2 published\_events.total=2 uptime={"server\_time":"2017-05-17T12:18:46.2367336Z","start\_time":"2017-05-17T12:16:16.1829183Z","uptime":"2m30.0538153s","uptime\_ms":"150053815"}  
2017-05-17T14:19:15+02:00 INFO EventLog[Microsoft-Windows-Sysmon/Operational] Successfully published 1 events

logstash is running fine on the receving machine and indexing firewall logs like a champ.  
if i try from the local machine with elastic search logstash and kibana and install winlogbeat, i also does not work. However if i set winlogbeat to send it directly to elasticsearch in the ie. localhost:9200 boom there is data.?

**localhost winlogbeat log**

libbeat.logstash.publish.write\_bytes=2927 libbeat.logstash.published\_but\_not\_acked\_events=2 published\_events.total=3  
2017-05-17T14:15:56+02:00 INFO No non-zero metrics in the last 30s

* * *

_2017-05-17T14:16:15+02:00 ERR Failed to publish events caused by: write tcp 127.0.0.1:63796-\>127.0.0.1:5044: wsasend: An existing connection was forcibly closed by the remote host._  
_2017-05-17T14:16:15+02:00 INFO Error publishing events (retrying): write tcp 127.0.0.1:63796-\>127.0.0.1:5044: wsasend: An existing connection was forcibly closed by the remote host._

* * *

2017-05-17T14:16:16+02:00 INFO EventLog[Microsoft-Windows-Sysmon/Operational] Successfully published 2 events  
2017-05-17T14:16:26+02:00 INFO Non-zero metrics in the last 30s: published\_events.Microsoft-Windows-Sysmon/Operational=2 libbeat.logstash.publish.read\_bytes=12 libbeat.logstash.published\_and\_acked\_events=2 published\_events.total=2 libbeat.logstash.call\_count.PublishEvents=2 libbeat.logstash.published\_but\_not\_acked\_events=2 libbeat.logstash.publish.write\_errors=1 libbeat.logstash.publish.write\_bytes=1648 libbeat.publisher.published\_events=2 msg\_file\_cache.Microsoft-Windows-Sysmon/OperationalHits=2  
2017-05-17T14:16:56+02:00 INFO No non-zero metrics in the last 30s  
2017-05-17T14:17:13+02:00 INFO EventLog[Microsoft-Windows-Sysmon/Operational] Successfully published 2 events  
2017-05-17T14:17:18+02:00 INFO EventLog[Microsoft-Windows-Sysmon/Operational] Successfully published 3 events  
2017-05-17T14:17:26+02:00 INFO Non-zero metrics in the last 30s: libbeat.logstash.publish.write\_bytes=3232 libbeat.publisher.published\_events=5 libbeat.logstash.publish.read\_bytes=12 libbeat.logstash.call\_count.PublishEvents=2 published\_events.total=5

what gives

I have priviously tried with xpack installed and got no where so i moved back to my "old" setup as here the firewall log input into logstash was running. same result as the ELK with xpack activated.

firewall on the ELK is open on 5044 tcp/udp

netstat outbut on server with logstash

## C:\Elk\nssm\win64\>netstat -np TCP | find "5044" TCP 127.0.0.1:50439 127.0.0.1:50440 TIME\_WAIT TCP 127.0.0.1:50440 127.0.0.1:50441 TIME\_WAIT TCP 127.0.0.1:50441 127.0.0.1:50442 TIME\_WAIT TCP 127.0.0.1:50442 127.0.0.1:50443 TIME\_WAIT TCP 127.0.0.1:50443 127.0.0.1:50444 TIME\_WAIT TCP 127.0.0.1:50444 127.0.0.1:50445 TIME\_WAIT TCP 127.0.0.1:50445 127.0.0.1:50446 TIME\_WAIT TCP 127.0.0.1:50446 127.0.0.1:50447 TIME\_WAIT TCP 127.0.0.1:50447 127.0.0.1:50448 TIME\_WAIT TCP 127.0.0.1:50448 127.0.0.1:50449 TIME\_WAIT TCP 127.0.0.1:50449 127.0.0.1:50450 TIME\_WAIT TCP 127.0.0.1:55043 127.0.0.1:55044 TIME\_WAIT TCP 127.0.0.1:55044 127.0.0.1:55045 TIME\_WAIT TCP 127.0.0.1:65043 127.0.0.1:65044 TIME\_WAIT

## TCP [XXX.17.20.XXX:5044](http://XXX.17.20.XXX:5044) XXX.16.XXX.11:12098 ESTABLISHED

the shown connection is the remote machine

i have a feeling im missing something totally obvious here ☹

should i post the logstash/winlogbeat config files too?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [May 22, 2017, 5:10am UTC](https://discuss.elastic.co/t/logstash-vs-winlogbeats-from-external-machine/86102/2 "2017-05-22T05:10:38Z")

</div>

Make sure your SSL configuration is symmetrical, i.e. that it's either enabled in both Logstash and Winlogbeat or disabled in both places. Yes, posting your configuration files would be helpful. Make sure you format them as preformatted text (e.g. using the `</>` toolbar button).

---

<div class="post-metadata">

**Author:** ![ssi](https://avatars.discourse-cdn.com/v4/letter/s/a3d4f5/32.png) [@ssi](https://discuss.elastic.co/u/ssi)\
**Post date:** [May 22, 2017, 7:39am UTC](https://discuss.elastic.co/t/logstash-vs-winlogbeats-from-external-machine/86102/3 "2017-05-22T07:39:53Z")

</div>

hi magnus,

i solved it. it turned out i made a mistake in the output part of the logstash config. i initially change the input to tcp instead on beats in logstash - and this got the data into elasticsearh - total gibberish but none the less data. I then took a barebone beats logstash config and got readable data into logstash. following this i made the changes to the output section here is the working config

input {  
#sysmon via winlogbeat  
beats {  
port =\> 5044  
}

#firewall logs  
udp {  
port =\> 514  
type =\> "cisco-asa"  
}  
#netscaler logs  
#udp {  
#port =\> 600  
#type =\> "Netscaler"

# }

}  
#########################  
filter {

### netscaler filter

if [type] == "Netscaler" {  
grok {  
break\_on\_match =\> true  
match =\> [  
"message", "\<%{POSINT:syslog\_pri}\> %{DATE\_US}:%{TIME} GMT %{SYSLOGHOST:syslog\_hostname} %{GREEDYDATA:netscaler\_message} : %{DATA} %{IP:source\_ip}:%{POSINT:source\_port} - %{DATA} %{IP:vserver\_ip}:%{POSINT:vserver\_port} - %{DATA} %{IP:nat\_ip}:%{POSINT:nat\_port} - %{DATA} %{IP:destination\_ip}:%{POSINT:destination\_port} - %{DATA} %{DATE\_US:DELINK\_DATE}:%{TIME:DELINK\_TIME} GMT - %{DATA} %{POSINT:total\_bytes\_sent} - %{DATA} %{POSINT:total\_bytes\_recv}",  
"message", "\<%{POSINT:syslog\_pri}\> %{DATE\_US}:%{TIME} GMT %{SYSLOGHOST:syslog\_hostname} %{GREEDYDATA:netscaler\_message} : %{DATA} %{IP:source\_ip}:%{POSINT:source\_port} - %{DATA} %{IP:destination\_ip}:%{POSINT:destination\_port} - %{DATA} %{DATE\_US:START\_DATE}:%{TIME:START\_TIME} GMT - %{DATA} %{DATE\_US:END\_DATE}:%{TIME:END\_TIME} GMT - %{DATA} %{POSINT:total\_bytes\_sent} - %{DATA} %{POSINT:total\_bytes\_recv}",  
"message", "\<%{POSINT:syslog\_pri}\> %{DATE\_US}:%{TIME} GMT %{SYSLOGHOST:syslog\_hostname} %{GREEDYDATA:netscaler\_message} : %{DATA} %{INT:netscaler\_spcbid} - %{DATA} %{IP:clientip} - %{DATA} %{INT:netscaler\_client\_port} - %{DATA} %{IP:netscaler\_vserver\_ip} - %{DATA} %{INT:netscaler\_vserver\_port} %{GREEDYDATA:netscaler\_message} - %{DATA} %{WORD:netscaler\_session\_type}",  
"message", "\<%{POSINT:syslog\_pri}\> %{DATE\_US}:%{TIME} GMT %{SYSLOGHOST:syslog\_hostname} %{GREEDYDATA:netscaler\_message}"  
]  
}

```
       }

```

###cisco asa filter  
if [type] == "cisco-asa" {

# Split the syslog part and Cisco tag out of the message

```
grok {
  match => ["message", "%{CISCO_TAGGED_SYSLOG} %{GREEDYDATA:cisco_message}"]  
      }     

```

# Parse the syslog severity and facility

```
syslog_pri { }

```

# Parse the date from the "timestamp" field to the "@timestamp" field

```
date {
  match => ["timestamp",
    "MMM dd HH:mm:ss",
    "MMM d HH:mm:ss",
    "MMM dd yyyy HH:mm:ss",
    "MMM d yyyy HH:mm:ss"
  ]
  timezone => "Europe/Paris"
}
# Clean up redundant fields if parsing was successful
if "_grokparsefailure" not in [tags] {
  mutate {
    rename => ["cisco_message", "message"]
    remove_field => ["timestamp"]
  }
}
# Extract fields from the each of the detailed message types
# The patterns provided below are included in Logstash since 1.2.0
grok {
  match => [
    "message", "%{CISCOFW106001}",
    "message", "%{CISCOFW106006_106007_106010}",
    "message", "%{CISCOFW106014}",
    "message", "%{CISCOFW106015}",
    "message", "%{CISCOFW106021}",
    "message", "%{CISCOFW106023}",
    "message", "%{CISCOFW106100}",
    "message", "%{CISCOFW110002}",
    "message", "%{CISCOFW302010}",
    "message", "%{CISCOFW302013_302014_302015_302016}",
    "message", "%{CISCOFW302020_302021}",
    "message", "%{CISCOFW305011}",
    "message", "%{CISCOFW313001_313004_313008}",
    "message", "%{CISCOFW313005}",
    "message", "%{CISCOFW402117}",
    "message", "%{CISCOFW402119}",
    "message", "%{CISCOFW419001}",
    "message", "%{CISCOFW419002}",
    "message", "%{CISCOFW500004}",
    "message", "%{CISCOFW602303_602304}",
    "message", "%{CISCOFW710001_710002_710003_710005_710006}",
    "message", "%{CISCOFW713172}",
    "message", "%{CISCOFW733100}"
  ]
}

```

}

}

#### output section

output {

elasticsearch {  
hosts =\> "localhost:9200"  
manage\_template =\> false  
index =\> "%{[@metadata][beat]}-%{+YYYY.MM.dd}"  
document\_type =\> "%{[@metadata][type]}"  
user =\> "elastic"  
password =\> "changeme"  
}

if [type] == "cisco-asa" {  
elasticsearch { hosts =\> ["localhost:9200"]  
index =\> "cisco-asa-%{+YYYY.MM.dd}"  
user =\> "elastic"  
password =\> "changeme"  
}  
}  
if [type] == "Netscaler" {  
elasticsearch { hosts =\> ["localhost:9200"]  
index =\> "netscaler-%{+YYYY.MM.dd}"  
user =\> "elastic"  
password =\> "changeme"  
}  
}  
}

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 19, 2017, 7:40am UTC](https://discuss.elastic.co/t/logstash-vs-winlogbeats-from-external-machine/86102/4 "2017-06-19T07:40:06Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
