# Sending Windows security logs to a different LogStash endpoint - multiple logstash endpoints

**URL:** <https://discuss.elastic.co/t/sending-windows-security-logs-to-a-different-logstash-endpoint-multiple-logstash-endpoints/182392>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [May 23, 2019, 9:36am UTC](https://discuss.elastic.co/t/sending-windows-security-logs-to-a-different-logstash-endpoint-multiple-logstash-endpoints/182392 "2019-05-23T09:36:40Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![jjjwils](https://avatars.discourse-cdn.com/v4/letter/j/f07891/32.png) [@jjjwils](https://discuss.elastic.co/u/jjjwils)\
**Post date:** [May 23, 2019, 9:36am UTC](https://discuss.elastic.co/t/sending-windows-security-logs-to-a-different-logstash-endpoint-multiple-logstash-endpoints/182392/1 "2019-05-23T09:36:40Z")

</div>

Hi,

We have a requirement to send our security logs to a different LogStash endpoint - I've tried various configs in the WinLogBeat.yml file - but Im not sure if its possible.

I know on LogStash this is fairly easy to send to different ES endpoints/indices, but the same format doesnt seem to work in the WinLogBeat.yml - basically we want our inputs to be all logs, but to send the security logs specifically to a different LogStash endpoint.

Its fine if it duplicates and sends security logs to both - the only way I can currently see of achieving this is with 2 WinLogBeat instances, but was hoping to do it with just one.

Any help appreciated.

My best attempt was something like:

input {  
winlogbeat.event\_logs:

- name: Application  
fields: {log\_type: Application}
- name: Security  
fields: {log\_type: Security}
- name: System  
fields: {log\_type: System}  
}

filter {  
if [fields][log\_type] == "Security" {  
output.logstash:  
hosts:  
-   
ssl:  
- enabled: true  
index: winsec  
}  
}

But of course this format is more for LogStash and not for yml and hence fails so didnt continue.

---

<div class="post-metadata">

**Author:** ![pierhugues](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pierhugues/32/48383_2.png) [@pierhugues](https://discuss.elastic.co/u/pierhugues)\
**Post date:** [May 23, 2019, 7:24pm UTC](https://discuss.elastic.co/t/sending-windows-security-logs-to-a-different-logstash-endpoint-multiple-logstash-endpoints/182392/2 "2019-05-23T19:24:42Z")

</div>

> [@jjjwils](#):
>
> Its fine if it duplicates and sends security logs to both - the only way I can currently see of achieving this is with 2 WinLogBeat instances, but was hoping to do it with just one.

Hello, its not currently possible for Winlogbeat to send to more than one different output. There are a few ways to make it work:

1. Start two winlogbeat, which is what you are doing.
2. Send to a common logstash instance that will redirect the events to the others instances.
3. Use a queues that two different logstash will read.

The first is probably the easiest solution.

---

<div class="post-metadata">

**Author:** ![jjjwils](https://avatars.discourse-cdn.com/v4/letter/j/f07891/32.png) [@jjjwils](https://discuss.elastic.co/u/jjjwils)\
**Post date:** [May 28, 2019, 8:35am UTC](https://discuss.elastic.co/t/sending-windows-security-logs-to-a-different-logstash-endpoint-multiple-logstash-endpoints/182392/3 "2019-05-28T08:35:16Z")

</div>

Hi Pier,

Thanks for confirming this for me and anyone else - I had fun trying to achieve the impossible with the Beats config regardless 😄

KR,

J

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 25, 2019, 8:35am UTC](https://discuss.elastic.co/t/sending-windows-security-logs-to-a-different-logstash-endpoint-multiple-logstash-endpoints/182392/4 "2019-06-25T08:35:20Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
