# Shipping Logs to Logstash not Working

**URL:** <https://discuss.elastic.co/t/shipping-logs-to-logstash-not-working/102892>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [October 5, 2017, 6:24pm UTC](https://discuss.elastic.co/t/shipping-logs-to-logstash-not-working/102892 "2017-10-05T18:24:38Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![elaair](https://avatars.discourse-cdn.com/v4/letter/e/6f9a4e/32.png) [@elaair](https://discuss.elastic.co/u/elaair)\
**Post date:** [October 5, 2017, 6:24pm UTC](https://discuss.elastic.co/t/shipping-logs-to-logstash-not-working/102892/1 "2017-10-05T18:24:39Z")

</div>

I thought I would take moment today to see how I could ship Windows logs from endpoints to Elastic. I set up a basic winlogbeats, config shown below:

```auto
winlogbeat.event_logs:
  - name: Application
    #ignore_older: 24h
  - name: Security
    #ignore_older: 24h
  - name: System
    #ignore_older: 24h
  - name: Windows PowerShell
    #ignore_older: 24h
 
output.logstash:
  enabled: true
  hosts: ["10.148.82.187:905"]
  index: winlogbeat*

```

I then setup a very basic logstash config on my remote logstash/elastic instance

```auto
input {
beats { port => 905 }
}

filter {

} #close filter block

output {
# stdout { codec => rubydebug }
          elasticsearch { hosts => ["127.0.0.1:9200"] index => "winlogbeat*" }

} #close output block

```

I imported the template like this:

```auto
[root@HOST ~]# curl -XPUT 'localhost:9200/_template/winlogbeat*' -d@./winlogbeat.template.json
{"acknowledged":true}[root@HOST ~]# 

GET _cat/templates
contianmenttemplate_1 containment-* 0 
winlogbeat* winlogbeat-* 0 
logstash logstash-* 0 50001
template_1 te* 0 
filebeat filebeat-* 0 

```

I checked for the index:

```auto
GET _cat/indices
yellow open winlogbeat _a3GZ2snRjWCCyquIWfpOw 5 1 0 0 810b 810bm

```

I only see output when I use stdout and not elastic. What did I miss??

---

<div class="post-metadata">

**Author:** ![elaair](https://avatars.discourse-cdn.com/v4/letter/e/6f9a4e/32.png) [@elaair](https://discuss.elastic.co/u/elaair)\
**Post date:** [October 5, 2017, 10:21pm UTC](https://discuss.elastic.co/t/shipping-logs-to-logstash-not-working/102892/2 "2017-10-05T22:21:29Z")

</div>

I resolved this by re creating all the steps and specifying the index and not using a \* in the template creation.

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [October 6, 2017, 1:40am UTC](https://discuss.elastic.co/t/shipping-logs-to-logstash-not-working/102892/3 "2017-10-06T01:40:32Z")

</div>

See the documentation for [index](https://www.elastic.co/guide/en/beats/winlogbeat/current/elasticsearch-output.html#_index). You were literally using `winlogbeat*` as the index name rather than a daily index pattern.

And for the Logstash config to use with Beats see [Setting Up Logstash [For Use with Beats]](https://www.elastic.co/guide/en/beats/libbeat/5.6/logstash-installation.html#logstash-setup).

---

<div class="post-metadata">

**Author:** ![elaair](https://avatars.discourse-cdn.com/v4/letter/e/6f9a4e/32.png) [@elaair](https://discuss.elastic.co/u/elaair)\
**Post date:** [October 6, 2017, 2:57am UTC](https://discuss.elastic.co/t/shipping-logs-to-logstash-not-working/102892/4 "2017-10-06T02:57:37Z")

</div>

I realized that mistake after a short time, and corrected it, then it started to work! What do you know about enterprise deployments of winlogbeats? Say I was interested in replacing Snare or Splunk forwarder?

w

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 3, 2017, 2:57am UTC](https://discuss.elastic.co/t/shipping-logs-to-logstash-not-working/102892/5 "2017-11-03T02:57:42Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
