# Telnet - which IP address do i try to telnet to?

**URL:** <https://discuss.elastic.co/t/telnet-which-ip-address-do-i-try-to-telnet-to/327885>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [March 16, 2023, 9:20pm UTC](https://discuss.elastic.co/t/telnet-which-ip-address-do-i-try-to-telnet-to/327885 "2023-03-16T21:20:36Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![iqworks](https://avatars.discourse-cdn.com/v4/letter/i/a9a28c/32.png) [@iqworks](https://discuss.elastic.co/u/iqworks)\
**Post date:** [March 16, 2023, 9:20pm UTC](https://discuss.elastic.co/t/telnet-which-ip-address-do-i-try-to-telnet-to/327885/1 "2023-03-16T21:20:36Z")

</div>

Hi, I get this message in my winlogbeat logs :

{"file.name":"beater/winlogbeat.go","file.line":149},"message":"Winlogbeat is unable to load the ingest pipelines because the Elasticsearch output is not configured/enabled. If you have already loaded the ingest pipelines, you can ignore this warning.","service.name":"winlogbeat","ecs.version":"1.6.0"}

it was suggested that :  
That means winlogbeat can not connect to elasticsearch.

I wanted to try telnet, but i am not sure which IP address i should use, my ipconfig Ipv4, my WMware IP network Addresses or the static IP address i use to connect to the SOC?

thanks very much for your help or advice

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [March 17, 2023, 1:19am UTC](https://discuss.elastic.co/t/telnet-which-ip-address-do-i-try-to-telnet-to/327885/2 "2023-03-17T01:19:44Z")

</div>

You are most likely trying to run `.\winlogbeat setup -e` with the output pointed to something other than elasticsearch.

Please share the output section of winlogbeat.yml

Are you pointing to logstash?

Which is okay if that's what you intend to do.

---

<div class="post-metadata">

**Author:** ![iqworks](https://avatars.discourse-cdn.com/v4/letter/i/a9a28c/32.png) [@iqworks](https://discuss.elastic.co/u/iqworks)\
**Post date:** [March 17, 2023, 7:33pm UTC](https://discuss.elastic.co/t/telnet-which-ip-address-do-i-try-to-telnet-to/327885/3 "2023-03-17T19:33:28Z")

</div>

Hi Stephen, i continued with this title with another title because i dont think telnet is my exact issue.  
when you get time, please feel free to look at this link.

> [@Sysmon events not getting to SOC kibana or hunt - connection issues](https://discuss.elastic.co/t/sysmon-events-not-getting-to-soc-kibana-or-hunt-connection-issues/327966):
>
> Hi, i am using elasticsearch 8.6.2, Winlogbeat 8.6.2 and sysmon 74 I am trying the ELK system. The data gets into sysmon ok. There are probably many reasons. I was pointing to output.logstash because as I understand it, it gets data from more places than elasticsearch. I saw in a couple of places that logstash data will also wind up in elasticsearch for the pipeline to SO? I saw that you cannot have two yml outputs at the same time. I assume that as long as the elasticsearch service is runn…

thanks as usual for your help and advice

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 14, 2023, 9:33pm UTC](https://discuss.elastic.co/t/telnet-which-ip-address-do-i-try-to-telnet-to/327885/4 "2023-04-14T21:33:35Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
