# Setup time counter in Winlogbeats

**URL:** <https://discuss.elastic.co/t/setup-time-counter-in-winlogbeats/167612>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [February 8, 2019, 11:20am UTC](https://discuss.elastic.co/t/setup-time-counter-in-winlogbeats/167612 "2019-02-08T11:20:31Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![compsecstudent](https://avatars.discourse-cdn.com/v4/letter/c/9f8e36/32.png) [@compsecstudent](https://discuss.elastic.co/u/compsecstudent)\
**Post date:** [February 8, 2019, 11:20am UTC](https://discuss.elastic.co/t/setup-time-counter-in-winlogbeats/167612/1 "2019-02-08T11:20:31Z")

</div>

Is it possible for Winlogbeat to include a time counter, for example when it starts sending logs the time counter would start at 0 then go by minutes (or hours) when sending logs?

Or is there a way to capture Winlogbeats up-time? Maybe have a field like this "uptime":"18.30.11"

If this is not possible, would it be able to parse this information in Logstash?

Thanks

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [February 9, 2019, 2:00am UTC](https://discuss.elastic.co/t/setup-time-counter-in-winlogbeats/167612/2 "2019-02-09T02:00:37Z")

</div>

What are you trying to accomplish?

Winlogbeat has a [monitoring feature](https://www.elastic.co/guide/en/kibana/6.6/beats-page.html) that can send information, including uptime, to Elasticsearch.

Winlogbeat logs metrics every 30s that include uptime. You can configure Winlogbeat to write its logs to the Application event log such that it forwards its own logs. Then parse that log message to get the uptime (best to configure Winlogbeat to write JSON so it's easy to parse)

```auto
logging.json: true
logging.to_eventlog: true

```

---

<div class="post-metadata">

**Author:** ![compsecstudent](https://avatars.discourse-cdn.com/v4/letter/c/9f8e36/32.png) [@compsecstudent](https://discuss.elastic.co/u/compsecstudent)\
**Post date:** [February 10, 2019, 2:48pm UTC](https://discuss.elastic.co/t/setup-time-counter-in-winlogbeats/167612/3 "2019-02-10T14:48:27Z")

</div>

Thanks for the response, is it also possible to calculate the up-time for each beat using the timestamp in logstash?

I tried logging to event log but it sends too many logs doesn't capture the up-time every time. I just want to collect the amount of time that each beat runs in a separate field, if that's possible?

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [February 10, 2019, 3:48pm UTC](https://discuss.elastic.co/t/setup-time-counter-in-winlogbeats/167612/4 "2019-02-10T15:48:44Z")

</div>

> [@compsecstudent](#):
>
> I tried logging to event log but it sends too many logs doesn't capture the up-time every time.

You could filter what Winlogbeat logs are forwarded by using a [processor](https://www.elastic.co/guide/en/beats/winlogbeat/current/drop-event.html) such that is only sends the metric events that contain uptime.

> [@compsecstudent](#):
>
> is it also possible to calculate the up-time for each beat using the timestamp in logstash?

I can't think of any way to calculate the value since you don't know the start time. You can get the uptime from the [logs](https://www.elastic.co/guide/en/beats/winlogbeat/current/configuration-logging.html#_literal_logging_metrics_enabled_literal), the built-in [monitoring feature](https://www.elastic.co/guide/en/beats/winlogbeat/current/monitoring.html), or the HTTP [monitoring API](https://www.elastic.co/guide/en/beats/winlogbeat/current/http-endpoint.html).

---

<div class="post-metadata">

**Author:** ![compsecstudent](https://avatars.discourse-cdn.com/v4/letter/c/9f8e36/32.png) [@compsecstudent](https://discuss.elastic.co/u/compsecstudent)\
**Post date:** [February 10, 2019, 3:51pm UTC](https://discuss.elastic.co/t/setup-time-counter-in-winlogbeats/167612/5 "2019-02-10T15:51:53Z")

</div>

That's great, thanks for the help.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 10, 2019, 4:05pm UTC](https://discuss.elastic.co/t/setup-time-counter-in-winlogbeats/167612/6 "2019-03-10T16:05:14Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
