# Read encrypted windows event logs

**URL:** https://discuss.elastic.co/t/read-encrypted-windows-event-logs/297380
**Category:** Beats
**Tags:** windows, winlogbeat, elastic-agent
**Created:** [February 16, 2022, 2:39pm UTC](https://discuss.elastic.co/t/read-encrypted-windows-event-logs/297380 "2022-02-16T14:39:58Z")
**Posts on this page:** 6
**Page:** 1

<div class="post-metadata">

### Author: ![EliWallic](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/eliwallic/32/66544_2.png) [@EliWallic](https://discuss.elastic.co/u/EliWallic)
#### Post date: [February 16, 2022, 2:39pm UTC](https://discuss.elastic.co/t/read-encrypted-windows-event-logs/297380/1 "2022-02-16T14:39:58Z")

</div>

Hello community,

for security reasons I have some eventlogs encrypted with an certificate.  
Windows native its possible to decrypt them in order to get access again.

Is it also possible with winlogbeat or filebeat?

Best regards

---

<div class="post-metadata">

### Author: ![legoguy1000](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/legoguy1000/32/54301_2.png) [@legoguy1000](https://discuss.elastic.co/u/legoguy1000)
#### Post date: [February 16, 2022, 4:34pm UTC](https://discuss.elastic.co/t/read-encrypted-windows-event-logs/297380/2 "2022-02-16T16:34:09Z")

</div>

There is no native feature in the Beats yo do that.

---

<div class="post-metadata">

### Author: ![EliWallic](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/eliwallic/32/66544_2.png) [@EliWallic](https://discuss.elastic.co/u/EliWallic)
#### Post date: [February 16, 2022, 8:34pm UTC](https://discuss.elastic.co/t/read-encrypted-windows-event-logs/297380/3 "2022-02-16T20:34:13Z")

</div>

Hi @legoguy1000

thanks for the info. This would be a nice feature request pointing to endpoint security / environment security

Best Regards.

---

<div class="post-metadata">

### Author: ![legoguy1000](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/legoguy1000/32/54301_2.png) [@legoguy1000](https://discuss.elastic.co/u/legoguy1000)
#### Post date: [February 16, 2022, 9:10pm UTC](https://discuss.elastic.co/t/read-encrypted-windows-event-logs/297380/4 "2022-02-16T21:10:46Z")

</div>

The problem with that is there are so many ways this would be approached, I don't think it would be sustainable. Are you talking about encrypted files, windows event logs, encrypted text within log files, encrypted syslog.....?

---

<div class="post-metadata">

### Author: ![EliWallic](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/eliwallic/32/66544_2.png) [@EliWallic](https://discuss.elastic.co/u/EliWallic)
#### Post date: [February 16, 2022, 10:30pm UTC](https://discuss.elastic.co/t/read-encrypted-windows-event-logs/297380/5 "2022-02-16T22:30:31Z")

</div>

in my case - just the encrypted windows event logs

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [March 17, 2022, 12:31am UTC](https://discuss.elastic.co/t/read-encrypted-windows-event-logs/297380/6 "2022-03-17T00:31:03Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
