# Scanning Windows Registry entries for Elastic Serach deployments

**URL:** <https://discuss.elastic.co/t/scanning-windows-registry-entries-for-elastic-serach-deployments/146335>\
**Category:** Elasticsearch\
**Created:** [August 28, 2018, 12:11pm UTC](https://discuss.elastic.co/t/scanning-windows-registry-entries-for-elastic-serach-deployments/146335 "2018-08-28T12:11:05Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Kaustav\_Gupta](https://avatars.discourse-cdn.com/v4/letter/k/13edae/32.png) [@Kaustav\_Gupta](https://discuss.elastic.co/u/Kaustav_Gupta)\
**Post date:** [August 28, 2018, 12:11pm UTC](https://discuss.elastic.co/t/scanning-windows-registry-entries-for-elastic-serach-deployments/146335/1 "2018-08-28T12:11:05Z")

</div>

I am trying to discover elasticsearch deployments in windows machines. In my scanner I wanted to search for a particular registry setting which is created when we install elastic search in Windows. I can search for the .bat file but the scanner performs extremely slow in that case. A windows registry will be much quicker. Any help appreciated

---

<div class="post-metadata">

**Author:** ![forloop](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/forloop/32/9021_2.png) [@forloop](https://discuss.elastic.co/u/forloop)\
**Post date:** [August 29, 2018, 1:16am UTC](https://discuss.elastic.co/t/scanning-windows-registry-entries-for-elastic-serach-deployments/146335/2 "2018-08-29T01:16:46Z")

</div>

The zip archive distribution does not add any registry settings so it's going to be tricky to understand who may have it installed. The environment variables `ES_HOME` and `ES_PATH_CONF` _may_ be set which may give some indication but no guarantee.

The Windows MSI installer distribution adds some registry entries that can be retrieved with e.g. PowerShell

```auto
gci Registry::HKEY_LOCAL_MACHINE\SOFTWARE\Elastic\Elasticsearch

```

**BUT** note that these registry entries only exist in installer versions 6.2.0+

---

<div class="post-metadata">

**Author:** ![Kaustav\_Gupta](https://avatars.discourse-cdn.com/v4/letter/k/13edae/32.png) [@Kaustav\_Gupta](https://discuss.elastic.co/u/Kaustav_Gupta)\
**Post date:** [August 29, 2018, 6:39am UTC](https://discuss.elastic.co/t/scanning-windows-registry-entries-for-elastic-serach-deployments/146335/3 "2018-08-29T06:39:34Z")

</div>

Thanks a lot..

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 26, 2018, 6:39am UTC](https://discuss.elastic.co/t/scanning-windows-registry-entries-for-elastic-serach-deployments/146335/4 "2018-09-26T06:39:37Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
