# Testing Elastic Stack and winlogbeat / query exceeds 1000 shards

**URL:** <https://discuss.elastic.co/t/testing-elastic-stack-and-winlogbeat-query-exceeds-1000-shards/77923>\
**Category:** Elasticsearch\
**Created:** [March 9, 2017, 1:46am UTC](https://discuss.elastic.co/t/testing-elastic-stack-and-winlogbeat-query-exceeds-1000-shards/77923 "2017-03-09T01:46:17Z")\
**Posts on this page:** 1\
**Showing post:** 22

<div class="post-metadata">

**Author:** ![jkuang](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jkuang/32/72637_2.png) [@jkuang](https://discuss.elastic.co/u/jkuang)\
**Post date:** [March 10, 2017, 3:56pm UTC](https://discuss.elastic.co/t/testing-elastic-stack-and-winlogbeat-query-exceeds-1000-shards/77923/22 "2017-03-10T15:56:19Z")

</div>

@kernelpanic

I figured out why:

The ignore\_older is only set for the Application log in the config you provided. Use the following if you would like a 72h set for each event log.

```auto
  event_logs:
    - name: Application
      ignore_older: 72h 
    - name: Security
      ignore_older: 72h
    - name: System
      ignore_older: 72h 

```

---

_[View the full topic](https://discuss.elastic.co/t/testing-elastic-stack-and-winlogbeat-query-exceeds-1000-shards/77923)._
