# Monitoring Multiple Windows Event Channels with Custom Event Logs in ELK Stack

**URL:** <https://discuss.elastic.co/t/monitoring-multiple-windows-event-channels-with-custom-event-logs-in-elk-stack/375134>\
**Category:** Elastic Agent\
**Created:** [February 27, 2025, 8:29am UTC](https://discuss.elastic.co/t/monitoring-multiple-windows-event-channels-with-custom-event-logs-in-elk-stack/375134 "2025-02-27T08:29:05Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![ValentinL](https://avatars.discourse-cdn.com/v4/letter/v/4491bb/32.png) [@ValentinL](https://discuss.elastic.co/u/ValentinL)\
**Post date:** [February 27, 2025, 8:29am UTC](https://discuss.elastic.co/t/monitoring-multiple-windows-event-channels-with-custom-event-logs-in-elk-stack/375134/1 "2025-02-27T08:29:05Z")

</div>

Hello everyone,

I have an ELK stack to monitor various Windows events. I monitor my agents with the Fleet server and integrations.

I frequently use the "Custom Windows Event Logs" to target specific Event IDs I need.

I want to know if it's possible to target IDs from different channels, i.e., "Security" and "System"?

Thank you for your help!

---

<div class="post-metadata">

**Author:** ![Tortoise](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tortoise/32/147587_2.png) [@Tortoise](https://discuss.elastic.co/u/Tortoise)\
**Post date:** [March 2, 2025, 8:24am UTC](https://discuss.elastic.co/t/monitoring-multiple-windows-event-channels-with-custom-event-logs-in-elk-stack/375134/2 "2025-03-02T08:24:12Z")

</div>

Hi,

I think we can use

event\_logs:

- name: Security  
event\_id: [4624, 4634, 4672] # Successful login, logout, admin login
- name: System  
event\_id: [6005, 6006, 1074] # Event log started, stopped, system shutdown

winlog.channel The name of the channel from which this record was read. This value is one of the names from the `event_logs` collection in the configuration. keyword

Thanks!!
