# Send clamav logs to elk

**URL:** <https://discuss.elastic.co/t/send-clamav-logs-to-elk/221483>\
**Category:** Beats\
**Tags:** elastic-stack-security\
**Created:** [February 28, 2020, 8:04pm UTC](https://discuss.elastic.co/t/send-clamav-logs-to-elk/221483 "2020-02-28T20:04:55Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![tbhaxor](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tbhaxor/32/63588_2.png) [@tbhaxor](https://discuss.elastic.co/u/tbhaxor)\
**Post date:** [February 28, 2020, 8:04pm UTC](https://discuss.elastic.co/t/send-clamav-logs-to-elk/221483/1 "2020-02-28T20:04:56Z")

</div>

Hi there,

I would like to send the scan logs from file `c:\program files\clamav\clamd.logs` to elasticsearch and assign new index name like `clamav-scans-*`

The scan logs for clean file looks like

```auto
Sat Feb 29 01:23:41 2020 -> C:\Program Files\ClamAV\.\clamd.conf: OK

```

and the scan logs for malicious file looks like

```auto
Sat Feb 29 01:25:56 2020 -> C:\Users\Malware Test\Downloads\wildfire-test-pe-file.exe: Win.Malware.Generic-6856527-0 FOUND

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 27, 2020, 10:05pm UTC](https://discuss.elastic.co/t/send-clamav-logs-to-elk/221483/2 "2020-03-27T22:05:01Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
