# Problem getting Windows Event log inside ELK

**URL:** <https://discuss.elastic.co/t/problem-getting-windows-event-log-inside-elk/54043>\
**Category:** Logstash\
**Created:** [June 27, 2016, 1:10pm UTC](https://discuss.elastic.co/t/problem-getting-windows-event-log-inside-elk/54043 "2016-06-27T13:10:02Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Gennady\_Sorochan](https://avatars.discourse-cdn.com/v4/letter/g/77aa72/32.png) [@Gennady\_Sorochan](https://discuss.elastic.co/u/Gennady_Sorochan)\
**Post date:** [June 27, 2016, 1:10pm UTC](https://discuss.elastic.co/t/problem-getting-windows-event-log-inside-elk/54043/1 "2016-06-27T13:10:03Z")

</div>

Hey.  
We're test ELK for for accumulating logs from various systems.  
We're using ELK on Windows and nxlog to forward logs from the Windows servers to the ELK server.  
Getting IIS logs works fine.  
Once we're starting forward Windows event log - the Kibana gives us error like this:

 ![](https://us1.discourse-cdn.com/elastic/original/2X/e/e294a11d8fe5d6e4e18f33f72d57781ec5cc1971.jpg)

The config that we're using:

**nxlog.conf:**

define ROOT C:\Program Files (x86)\nxlog  
define ROOT\_STRING C:\Program Files (x86)\nxlog

Moduledir %ROOT%\modules  
CacheDir %ROOT%\data  
Pidfile %ROOT%\data\nxlog.pid  
SpoolDir %ROOT%\data  
LogFile %ROOT%\data\nxlog.log

 Module xm\_charconv AutodetectCharsets utf-8, euc-jp, utf-16, utf-32, iso8859-2 Module xm\_json
# Windows Event Log
 Module im\_msvistalog SavePos FALSE ReadFromLast TRUE PollInterval 2 Query \ \ \*\ \ Exec convert\_fields("AUTO", "utf-8"); Exec to\_json(); Module om\_tcp Host ELK.local Port 10511

\<Route 1\>  
Path Win\_Eventlog =\> out

* * *

**logstash.conf:**

input {  
udp {  
port =\> 5000  
codec =\> plain { charset =\> "UTF-8" }  
type =\> "log4net-yellow"  
}

```
udp {
	port => 5001
	type => "syslog"
}

udp { 
	port => 5002 
	codec => plain { charset => "UTF-8" } 
	type => "log4net-blue" 
}

udp { 
	port => 5003 
	codec => plain { charset => "UTF-8" } 
	type => "kpi" 
}

tcp {
	port => 10511
	codec => json
	type => "Win_Eventlog-1"
}
 beats {
    port => 20515
  }

```

}

filter {  
if [type] == "log4net-yellow" {  
grok {  
patterns\_dir =\> "../../patterns-1-master"  
remove\_field =\> message  
match =\> { message =\> "(?m)%{TIMESTAMP\_ISO8601:sourceTimestamp} [%{NUMBER:threadid}] %{LOGLEVEL:loglevel} +- %{IPORHOST:tempHost} - %{GREEDYDATA:tempMessage}" }  
}

```
	if !("_grokparsefailure" in [tags]) {
		mutate {
			replace => ["message" , "%{tempMessage}"]
			replace => ["host" , "%{tempHost}"]
		}
	}
	mutate {
		remove_field => ["tempMessage"]
		remove_field => ["tempHost"]
		}
	}
	
if [type] == "log4net-blue" {
	grok {
		patterns_dir => "../../patterns-1-master"
		remove_field => message
		match => { message => "(?m)%{TIMESTAMP_ISO8601:sourceTimestamp} \[%{NUMBER:threadid}\] %{LOGLEVEL:loglevel} +- %{IPORHOST:tempHost} - %{GREEDYDATA:tempMessage}" }
	}

	if !("_grokparsefailure" in [tags]) {
		mutate {
			replace => ["message" , "%{tempMessage}"]
			replace => ["host" , "%{tempHost}"]
		}
	}
	mutate {
		remove_field => ["tempMessage"]
		remove_field => ["tempHost"]
		}
	}
	

if [type] == "Win_Eventlog-1" {
    if [SourceModuleName] == "eventlog" {
        mutate {
            replace => ["message", "%{Message}"]
        	    }
        mutate {
            remove_field => ["Message"]
        	   }
    				     }
}
				}

```

output {  
elasticsearch {  
hosts =\> ["localhost:9200"]  
}  
}

* * *

I've also tryed to send logs using:  
Exec $EventReceivedTime = integer($EventReceivedTime) / 1000000; to\_json();  
no json just: Exec convert\_fields("AUTO", "utf-8");

and put in logstash.conf:  
codec =\> json\_lines { charset =\> CP1252 }  
codec =\> plain { charset =\> "UTF-8" }

Always the same result....

What goes wrong?

Many thanks!!!!  
Gennady

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [June 29, 2016, 12:44am UTC](https://discuss.elastic.co/t/problem-getting-windows-event-log-inside-elk/54043/2 "2016-06-29T00:44:54Z")

</div>

Check your Kibana logs for more details.

---

<div class="post-metadata">

**Author:** ![Gennady\_Sorochan](https://avatars.discourse-cdn.com/v4/letter/g/77aa72/32.png) [@Gennady\_Sorochan](https://discuss.elastic.co/u/Gennady_Sorochan)\
**Post date:** [June 29, 2016, 9:28am UTC](https://discuss.elastic.co/t/problem-getting-windows-event-log-inside-elk/54043/3 "2016-06-29T09:28:57Z")

</div>

In order to isolate the issue and not to mess with the ELK that is working good for IIS - i've installed separate ELK instance just to work on windows events. The instance is up and running and logstash accepts data fron remote nxlog client.  
The kibana error still the same.  
Attached links to stdout from logstash and kibana.

[https://drive.google.com/file/d/0B5naKByXjZEvZ2VCSG5iRHVrS2s/view?usp=sharing](https://drive.google.com/file/d/0B5naKByXjZEvZ2VCSG5iRHVrS2s/view?usp=sharing)

[https://drive.google.com/file/d/0B5naKByXjZEvNlBGLTZLc2Y2eFU/view?usp=sharing](https://drive.google.com/file/d/0B5naKByXjZEvNlBGLTZLc2Y2eFU/view?usp=sharing)

The logstash message looks good (i think).

Still not getting why kibana is doing this...

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:50am UTC](https://discuss.elastic.co/t/problem-getting-windows-event-log-inside-elk/54043/4 "2017-07-06T04:50:28Z")

</div>


