# Standalone Elastic Agent Winlog System Input

**URL:** <https://discuss.elastic.co/t/standalone-elastic-agent-winlog-system-input/381693>\
**Category:** Elastic Agent\
**Tags:** filebeat\
**Created:** [September 6, 2025, 1:59pm UTC](https://discuss.elastic.co/t/standalone-elastic-agent-winlog-system-input/381693 "2025-09-06T13:59:17Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![s.buksa](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/s.buksa/32/124525_2.png) [@s.buksa](https://discuss.elastic.co/u/s.buksa)\
**Post date:** [September 6, 2025, 1:59pm UTC](https://discuss.elastic.co/t/standalone-elastic-agent-winlog-system-input/381693/1 "2025-09-06T13:59:17Z")

</div>

I am trying to collect System logs from Windows Servers with Standalone Elastic Agent. While necessary System logs are being correctly picked up and indexed into Elasticsearch with Winlogbeat, Elastic Agent causes some issues.

Running agent from: **elastic-agent-9.1.3-windows-x86\_64**  
Basic content of **elastic-agent.yml** file:

```auto
outputs:
  default:
  type: elasticsearch
  hosts: ["elasticsearch-address"]
  api_key: "elastic-agent-api-key"
  preset: balanced

agent:
  monitoring:
  enabled: false
  use_output: default
  logs: false
  metrics: false
  traces: false
  namespace: default

inputs:
  - id: windows-event-log
    name: System
    type: winlog
    use_output: default
    meta:
      package:
        name: winlog
        version: 2.4.0
    data_stream:
      namespace: default
    streams:
      - name: System
        data_stream:
          dataset: system.system
          type: logs
        condition: '${host.platform} == "windows"'
        event_id: 6006

agent.logging.level: debug

agent.logging.to_stderr: true

providers:
  agent:
    enabled: true
  host:
    enabled: true

```

I can see that it picks System data and index named **logs-system.system-default** appears in Elastic but without a single document. When checking elastic-agent-event-log there are errors containing the following message:

```auto
{"type":"document_parsing_exception","reason":"\[1:539\] Cannot write to a field alias \[host.hostname\]."}, dropping event!","component":{"binary":"filebeat","dataset":"elastic_agent.filebeat","id":"winlog-default","type":"winlog"},"log":{"source":"winlog-default"},"ecs.version":"1.6.0","log.logger":"elasticsearch.elasticsearch","log.origin":{"file.line":535,"file.name":"elasticsearch/client.go"

```

and all event data goes under "raw\_index". How to solve the issue? Am I missing something in **elastic-agent.yml** configuration?

---

<div class="post-metadata">

**Author:** ![s.buksa](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/s.buksa/32/124525_2.png) [@s.buksa](https://discuss.elastic.co/u/s.buksa)\
**Post date:** [September 6, 2025, 10:22pm UTC](https://discuss.elastic.co/t/standalone-elastic-agent-winlog-system-input/381693/2 "2025-09-06T22:22:42Z")

</div>

Hi @leandrojmp (or anyone else from the team),

Could someone please take a look at this?

I'm cannot determine if it's a misconfiguration on my end or a deeper issue. I've already reviewed the documentation and scanned through several issues, but haven't found a clear solution yet.

If someone from the team could help clarify or guide me in the right direction, I’d really appreciate it!

Thanks in advance 🙏

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [September 7, 2025, 9:27am UTC](https://discuss.elastic.co/t/standalone-elastic-agent-winlog-system-input/381693/3 "2025-09-07T09:27:46Z")

</div>

> [@s.buksa](#):
>
> ```auto
> condition: '${host.platform} == "windows"'
> 
> ```

Have you tried without the condition?

---

<div class="post-metadata">

**Author:** ![s.buksa](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/s.buksa/32/124525_2.png) [@s.buksa](https://discuss.elastic.co/u/s.buksa)\
**Post date:** [September 7, 2025, 10:42am UTC](https://discuss.elastic.co/t/standalone-elastic-agent-winlog-system-input/381693/4 "2025-09-07T10:42:57Z")

</div>

Yes, I have tried without condition and also without providers section. Got the same error message.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [September 7, 2025, 3:53pm UTC](https://discuss.elastic.co/t/standalone-elastic-agent-winlog-system-input/381693/5 "2025-09-07T15:53:59Z")

</div>

Hi @s.buksa

What version of the stack are you on?

`Cannot write to a field alias \[host.hostname\]."},` This is the issue all the docs are being dropped.

Have you created your own template or edited the default one because `host.hostname` should not be set as an alias type? AFAIK. So when `host.hostname` comes in as a field and the type for that field is `alias` then the document mapping will have a collision and the document will fail to be written.

> [@s.buksa](#):
>
> I can see that it picks System data and index named **logs-system.system-default**

Needing to be precise, is that an Index or a Data Stream...

Can you get the mapping for that index should be something like and share that specifically the mapping for `host.hostname`

`GET .ds-logs-system.system-default-2025.09.07-000341`

> [@s.buksa](#):
>
> and all event data goes under "raw\_index". How to solve the issue? Am I missing something in **elastic-agent.yml** configuration?

And I am confused you said there was no data or is this a different problem... lets fix one thing at a time

---

<div class="post-metadata">

**Author:** ![s.buksa](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/s.buksa/32/124525_2.png) [@s.buksa](https://discuss.elastic.co/u/s.buksa)\
**Post date:** [September 7, 2025, 4:44pm UTC](https://discuss.elastic.co/t/standalone-elastic-agent-winlog-system-input/381693/6 "2025-09-07T16:44:37Z")

</div>

Hi @stephenb

Elastic Stack version: 8.18.3

I haven’t created my own template or edited any existing ones.

The `logs-system.system-default` index appeared in Elasticsearch after I ran the Elastic Agent, but it doesn't contain any documents. There is no data stream associated with `logs-system.system-default`

Regarding the `raw_index` error logged by Elastic Agent - appears in the file: `elastic-agent/data/elastic-agent-*/logs/events/elastic-agent-event-log-*.ndjson`.

These logs show that the data is picked up successfully, but fails during indexing due to: `"Cannot write to a field alias [host.hostname]"`

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [September 7, 2025, 5:00pm UTC](https://discuss.elastic.co/t/standalone-elastic-agent-winlog-system-input/381693/7 "2025-09-07T17:00:34Z")

</div>

So lets do 1 things at a time

First I would not use agent 9.1.3 with stack 8.18; use the same version agent, especially not a "future" version

> [@s.buksa](#):
>
> The `logs-system.system-default` index appeared in Elasticsearch after I ran the Elastic Agent, but it doesn't contain any documents. There is no data stream associated with `logs-system.system-default`

That does not make sense... Show me...

Run these and show the results

```auto
GET _cat/indices/*system.system*?v

GET _data_stream/logs-system.system-default

```

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [September 7, 2025, 5:07pm UTC](https://discuss.elastic.co/t/standalone-elastic-agent-winlog-system-input/381693/8 "2025-09-07T17:07:25Z")

</div>

Ohh super important and did you actually add the System Integration in Kibana?  
Otherwise the mapping / parsing etc.. Ingest PIpeline will not work!  
You have to actually install it

 ![Screenshot 2025-09-07 at 10.20.55 AM](https://us1.discourse-cdn.com/elastic/original/3X/9/3/93f95c4890909f8d6ce3ac7d0f3fc28270666396.png)

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [September 7, 2025, 5:31pm UTC](https://discuss.elastic.co/t/standalone-elastic-agent-winlog-system-input/381693/9 "2025-09-07T17:31:36Z")

</div>

~~Here is a configuration that I have running this is from fleet managaed but should be the same.~~

Here is one I generated for standalone  
You can generate these through the UI, Just create a blank policy, add the integration, add agent standalone...

```auto
inputs:
  - id: winlog-system-ec05beac-9137-41ed-98fa-38d0d30a8697
    name: system-logs-only
    revision: 2
    type: winlog
    use_output: default
    meta:
      package:
        name: system
        version: 2.5.4
    data_stream:
      namespace: default
    package_policy_id: ec05beac-9137-41ed-98fa-38d0d30a8697
    streams:
      - id: winlog-system.system-ec05beac-9137-41ed-98fa-38d0d30a8697
        name: System
        data_stream:
          dataset: system.system
          type: logs
        condition: ${host.platform} == 'windows'
        ignore_older: 72h

```

BTW Your outputs above do not look correctly indented.

```auto
outputs:
  default:
    api_key: <REDACTED>
    hosts:
    - https://mydeployment12345.us-west1.gcp.cloud.es.io:443
    preset: balanced
    type: elasticsearch

```

---

<div class="post-metadata">

**Author:** ![s.buksa](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/s.buksa/32/124525_2.png) [@s.buksa](https://discuss.elastic.co/u/s.buksa)\
**Post date:** [September 7, 2025, 7:29pm UTC](https://discuss.elastic.co/t/standalone-elastic-agent-winlog-system-input/381693/10 "2025-09-07T19:29:20Z")

</div>

The output indentation in the configuration is correct - I believe it was lost here during formatting.  
Thanks a lot for the rest of the information. 🙏 I'll double check everything tomorrow.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [September 7, 2025, 8:58pm UTC](https://discuss.elastic.co/t/standalone-elastic-agent-winlog-system-input/381693/11 "2025-09-07T20:58:32Z")

</div>

You can do this from UI

 ![Screenshot 2025-09-07 at 1.57.21 PM](https://us1.discourse-cdn.com/elastic/original/3X/c/8/c8bf9d3ae551c6993b6bda8b07efb524359b84bd.png)

 ![Screenshot 2025-09-07 at 1.57.29 PM](https://us1.discourse-cdn.com/elastic/original/3X/2/9/291ad186ea29a0107d643c34f919644ea7858f1a.png)

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [September 7, 2025, 11:10pm UTC](https://discuss.elastic.co/t/standalone-elastic-agent-winlog-system-input/381693/13 "2025-09-07T23:10:38Z")

</div>

@6mil Welcome to the community.

Assuming your response was not AI generated...

It's a good question clarification..

There is a difference and often confusion about

Windows system logs  
vs  
And windows event logs

Your response is about event logs, but I think the original poster is interested in system logs.

Let's see...
