# Send Windows Log to Logstash Server

**URL:** <https://discuss.elastic.co/t/send-windows-log-to-logstash-server/560>\
**Category:** Logstash\
**Created:** [May 12, 2015, 3:00pm UTC](https://discuss.elastic.co/t/send-windows-log-to-logstash-server/560 "2015-05-12T15:00:08Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![SJ04](https://avatars.discourse-cdn.com/v4/letter/s/d26b3c/32.png) [@SJ04](https://discuss.elastic.co/u/SJ04)\
**Post date:** [May 12, 2015, 3:00pm UTC](https://discuss.elastic.co/t/send-windows-log-to-logstash-server/560/1 "2015-05-12T15:00:08Z")

</div>

Hi there!

I know, this topic have been discussed many time before on this Platform, But i still have some issue with Receving Log from the Windows Platform to Logstash Server.

Logstash Server: Ubuntu.

i have tried to get the log Via NXlog and SysLog agent but it still doesnt work.

can someone pass me a link or any help , how to configure this.

thanks

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [May 12, 2015, 3:20pm UTC](https://discuss.elastic.co/t/send-windows-log-to-logstash-server/560/2 "2015-05-12T15:20:31Z")

</div>

What doesn't work? Are you talking about the Windows Event Log or text files? Is NXLog is able to read events but fails when shipping the messages? Is Logstash receiving the messages but not able to parse them correctly?

---

<div class="post-metadata">

**Author:** ![SJ04](https://avatars.discourse-cdn.com/v4/letter/s/d26b3c/32.png) [@SJ04](https://discuss.elastic.co/u/SJ04)\
**Post date:** [May 12, 2015, 4:12pm UTC](https://discuss.elastic.co/t/send-windows-log-to-logstash-server/560/3 "2015-05-12T16:12:13Z")

</div>

> [@magnusbaeck](#):
>
> Is NXLog is able to read

Hi there,  
I have both Machine in the Same subnet and i can access the log from linux machine(Cent OS) via Logstash(agent) over the redis (Port 6379) but when i try to sip the logs from windows Machine to Logstash Server Via NXLOG,  
it gves me this error. and i am using Port TCP port 3515.

**No connection could be made because the target machine actively refused it**

\*\*

- Config file over the Logstash Server

\*\*  
tcp {  
type =\> "eventlog"  
port =\> 3515  
codec =\> "line"  
}

and NXLOG Config File  
  
Module om\_tcp  
Host 10.30.0.175  
Port 3515

Looks Like this.

thanks

---

<div class="post-metadata">

**Author:** ![SJ04](https://avatars.discourse-cdn.com/v4/letter/s/d26b3c/32.png) [@SJ04](https://discuss.elastic.co/u/SJ04)\
**Post date:** [May 12, 2015, 6:01pm UTC](https://discuss.elastic.co/t/send-windows-log-to-logstash-server/560/4 "2015-05-12T18:01:29Z")

</div>

Hi there!!

now all is working! i can see the windows log within Kibana Interface.

But its sending all the Logs! I just need to filter some useful info.

**SOLUTION**  
what i did!!

**NXLOG Set UP**

## Please set the ROOT to the folder your nxlog was installed into,

## otherwise it will not start.

#define ROOT C:\Program Files\nxlog  
define ROOT C:\Program Files (x86)\nxlog

Moduledir %ROOT%\modules  
CacheDir %ROOT%\data  
Pidfile %ROOT%\data\nxlog.pid  
SpoolDir %ROOT%\data  
LogFile %ROOT%\data\nxlog.log

 Module xm\_json
# Nxlog internal logs
 Module im\_internal Exec $EventReceivedTime = integer($EventReceivedTime) / 1000000; to\_json();
# Windows Event Log
# Uncomment im\_msvistalog for Windows Vista/2008 and later Module im\_msvistalog
# Uncomment im\_mseventlog for Windows XP/2000/2003

# Module im\_mseventlog

Exec $EventReceivedTime = integer($EventReceivedTime) / 1000000; to\_json();

 Module om\_tcp Host \*\*Logstash Server IP\*\* Port 3515

\<Route 1\>  
Path internal, eventlog =\> out

\*\*LOGstash Config File  
\*\*

tcp {  
codec =\> json\_lines { charset =\> CP1252 }  
port =\> "3515"  
tags =\> ["tcpjson"]  
}

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:39am UTC](https://discuss.elastic.co/t/send-windows-log-to-logstash-server/560/5 "2017-07-06T05:39:58Z")

</div>


