# Sending Event Logs and Log Files

**URL:** <https://discuss.elastic.co/t/sending-event-logs-and-log-files/142860>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [August 3, 2018, 7:40am UTC](https://discuss.elastic.co/t/sending-event-logs-and-log-files/142860 "2018-08-03T07:40:39Z")\
**Posts on this page:** 16\
**Page:** 1

<div class="post-metadata">

**Author:** ![Badb0y](https://avatars.discourse-cdn.com/v4/letter/b/50afbb/32.png) [@Badb0y](https://discuss.elastic.co/u/Badb0y)\
**Post date:** [August 3, 2018, 7:40am UTC](https://discuss.elastic.co/t/sending-event-logs-and-log-files/142860/1 "2018-08-03T07:40:39Z")

</div>

Is there anybody can help me, how to configure the winlogbeat to send these logs?

define BASEDIR D:\sdfdsfs\LogFiles\zip\_archive File '%BASEDIR%\www.vvv.com\u\*.log' Module im\_file File '%BASEDIR%\www81.vvv.com\u\*.log' Module im\_file File '%BASEDIR%\http\_sys\_logs\HTTPERR\h\*.log'

How can I define this in the config yml?

I'm using 6.2.4 version and we would like to install winglobeat around 3000 servers but we should know how we can configure this.

Very appreciate any help.

The current config is basic like this:

winlogbeat.event\_logs:

- name: Application  
ignore\_older: 72h
- name: Security
- name: System
- name: Specialeventlog  
output.logstash:  
hosts: ["server:5054"]

I'd like to extend this according to my table.

---

<div class="post-metadata">

**Author:** ![kvch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kvch/32/72058_2.png) [@kvch](https://discuss.elastic.co/u/kvch)\
**Post date:** [August 3, 2018, 8:26am UTC](https://discuss.elastic.co/t/sending-event-logs-and-log-files/142860/2 "2018-08-03T08:26:42Z")

</div>

Where is that log coming from? What's the ID of that event?

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [August 3, 2018, 2:27pm UTC](https://discuss.elastic.co/t/sending-event-logs-and-log-files/142860/3 "2018-08-03T14:27:04Z")

</div>

I think you are trying to ingest a file to Elasticsearch. For that, use Filebeat. Winlogbeat only does Windows event logs. If you need to ingest both event logs and log files then install both Winlogbeat and Filebeat together on your Windows host.

---

<div class="post-metadata">

**Author:** ![Badb0y](https://avatars.discourse-cdn.com/v4/letter/b/50afbb/32.png) [@Badb0y](https://discuss.elastic.co/u/Badb0y)\
**Post date:** [August 5, 2018, 4:22am UTC](https://discuss.elastic.co/t/sending-event-logs-and-log-files/142860/4 "2018-08-05T04:22:21Z")

</div>

Hi Noemi, I don't know yet, still waiting for the information from the team, but you are asking because if it has an id, it means it reports to one of the windows log so we can define it from the winevt directory and can filter after?

---

<div class="post-metadata">

**Author:** ![Badb0y](https://avatars.discourse-cdn.com/v4/letter/b/50afbb/32.png) [@Badb0y](https://discuss.elastic.co/u/Badb0y)\
**Post date:** [August 5, 2018, 4:24am UTC](https://discuss.elastic.co/t/sending-event-logs-and-log-files/142860/5 "2018-08-05T04:24:04Z")

</div>

Yes, exactly, I want to ingest logs to elastic search. With filebeat for windows can ingest files and event logs as well? I just recognized we have filebeat for windows not only for linux.

---

<div class="post-metadata">

**Author:** ![kvch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kvch/32/72058_2.png) [@kvch](https://discuss.elastic.co/u/kvch)\
**Post date:** [August 6, 2018, 8:38am UTC](https://discuss.elastic.co/t/sending-event-logs-and-log-files/142860/6 "2018-08-06T08:38:49Z")

</div>

Yes, you can use Filebeat on Windows to collect logs from files. The configuration is done the same way as on Linux.

---

<div class="post-metadata">

**Author:** ![Badb0y](https://avatars.discourse-cdn.com/v4/letter/b/50afbb/32.png) [@Badb0y](https://discuss.elastic.co/u/Badb0y)\
**Post date:** [August 6, 2018, 5:21pm UTC](https://discuss.elastic.co/t/sending-event-logs-and-log-files/142860/7 "2018-08-06T17:21:49Z")

</div>

How about the event logs?

---

<div class="post-metadata">

**Author:** ![kvch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kvch/32/72058_2.png) [@kvch](https://discuss.elastic.co/u/kvch)\
**Post date:** [August 7, 2018, 11:15am UTC](https://discuss.elastic.co/t/sending-event-logs-and-log-files/142860/8 "2018-08-07T11:15:10Z")

</div>

You need Winlogbeat for that. So it means that you need to run two Beats in parallel; one Filebeat to collect log files and one Winlogbeat to collect event logs.

---

<div class="post-metadata">

**Author:** ![Badb0y](https://avatars.discourse-cdn.com/v4/letter/b/50afbb/32.png) [@Badb0y](https://discuss.elastic.co/u/Badb0y)\
**Post date:** [August 14, 2018, 6:47am UTC](https://discuss.elastic.co/t/sending-event-logs-and-log-files/142860/9 "2018-08-14T06:47:19Z")

</div>

I haven't tried this yet, but how about this one:

> [@Using Winlogbeat for custom logfiles?](https://discuss.elastic.co/t/using-winlogbeat-for-custom-logfiles/100482/6):
>
> Yeah Winlogbeat is dedicated to Windows Event logs. For your Application logs you can use Filebeat [https://www.elastic.co/products/beats](https://www.elastic.co/products/beats) to send your application log data to Elastic. Alternatively to Filebeat you can use the "File" input plugin (included by default) in Logstash [https://www.elastic.co/products/logstash](https://www.elastic.co/products/logstash). Logstash is the heavy duty option in that it has plenty of options to perform a lot transformation and filtering (can use grok) on the data before it sends it on to Elastic. So d…

---

<div class="post-metadata">

**Author:** ![kvch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kvch/32/72058_2.png) [@kvch](https://discuss.elastic.co/u/kvch)\
**Post date:** [August 14, 2018, 6:59am UTC](https://discuss.elastic.co/t/sending-event-logs-and-log-files/142860/10 "2018-08-14T06:59:01Z")

</div>

If you only need to forward logs to an output, you should go with Filebeat. It's more lightweight than Logstash. Do you want to transform and/or use advanced filtering on your logs? If yes, choose Logstash.

---

<div class="post-metadata">

**Author:** ![Badb0y](https://avatars.discourse-cdn.com/v4/letter/b/50afbb/32.png) [@Badb0y](https://discuss.elastic.co/u/Badb0y)\
**Post date:** [August 14, 2018, 7:10am UTC](https://discuss.elastic.co/t/sending-event-logs-and-log-files/142860/11 "2018-08-14T07:10:04Z")

</div>

I just want to send logs from event logs and from files.

---

<div class="post-metadata">

**Author:** ![kvch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kvch/32/72058_2.png) [@kvch](https://discuss.elastic.co/u/kvch)\
**Post date:** [August 14, 2018, 7:22am UTC](https://discuss.elastic.co/t/sending-event-logs-and-log-files/142860/12 "2018-08-14T07:22:49Z")

</div>

Then I think you should stick with Filebeat. You just need to configure the path to the log files and set the output. See more here on how to configure Filebeat: [https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-configuration.html](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-configuration.html)  
Getting started guide: [https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-getting-started.html](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-getting-started.html)

---

<div class="post-metadata">

**Author:** ![Badb0y](https://avatars.discourse-cdn.com/v4/letter/b/50afbb/32.png) [@Badb0y](https://discuss.elastic.co/u/Badb0y)\
**Post date:** [August 14, 2018, 8:26am UTC](https://discuss.elastic.co/t/sending-event-logs-and-log-files/142860/13 "2018-08-14T08:26:37Z")

</div>

Yeye, but in case of event logs?

---

<div class="post-metadata">

**Author:** ![kvch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kvch/32/72058_2.png) [@kvch](https://discuss.elastic.co/u/kvch)\
**Post date:** [August 14, 2018, 8:32am UTC](https://discuss.elastic.co/t/sending-event-logs-and-log-files/142860/14 "2018-08-14T08:32:31Z")

</div>

For event logs you need Winlogbeat, which is a separate Beat. You can find the getting started guide here: [https://www.elastic.co/guide/en/beats/winlogbeat/master/winlogbeat-getting-started.html](https://www.elastic.co/guide/en/beats/winlogbeat/master/winlogbeat-getting-started.html)

---

<div class="post-metadata">

**Author:** ![Badb0y](https://avatars.discourse-cdn.com/v4/letter/b/50afbb/32.png) [@Badb0y](https://discuss.elastic.co/u/Badb0y)\
**Post date:** [August 22, 2018, 8:51am UTC](https://discuss.elastic.co/t/sending-event-logs-and-log-files/142860/15 "2018-08-22T08:51:16Z")

</div>

I've installed filebeat next to the winlogbeat now, so I'd like to send these logs:

from this directory:  
Let's call this as a basedir: D:\httplogs\LogFiles\zip\_archive

These logs:  
'%BASEDIR%\[www.sd.com](http://www.sd.com)\u\*.log'  
and if the logs:  
if $raw\_event =~ /^#/ drop();  
just drop it

and in our old configuration it was:  
$SourceName = 'web\_return\_code';

Here is the config actually that I want to replace.  
[https://pastebin.com/raw/eJx3vKQt](https://pastebin.com/raw/eJx3vKQt)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 19, 2018, 8:51am UTC](https://discuss.elastic.co/t/sending-event-logs-and-log-files/142860/16 "2018-09-19T08:51:22Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
