# Unable to install "logstash-input-eventlog" plugin (windows event viewer logs)

**URL:** <https://discuss.elastic.co/t/unable-to-install-logstash-input-eventlog-plugin-windows-event-viewer-logs/102388>\
**Category:** Logstash\
**Created:** [October 1, 2017, 7:58pm UTC](https://discuss.elastic.co/t/unable-to-install-logstash-input-eventlog-plugin-windows-event-viewer-logs/102388 "2017-10-01T19:58:29Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![scch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/scch/32/25504_2.png) [@scch](https://discuss.elastic.co/u/scch)\
**Post date:** [October 1, 2017, 7:58pm UTC](https://discuss.elastic.co/t/unable-to-install-logstash-input-eventlog-plugin-windows-event-viewer-logs/102388/1 "2017-10-01T19:58:29Z")

</div>

[root@redes logstash]# logstash-plugin install logstash-input-eventlog  
Validating logstash-input-eventlog  
Installing logstash-input-eventlog  
Error Bundler::InstallError, retrying 1/10  
An error occurred while installing logstash-core (5.6.2), and Bundler cannot continue.  
Make sure that `gem install logstash-core -v '5.6.2'` succeeds before bundling.

Request help to resolve

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [October 1, 2017, 9:33pm UTC](https://discuss.elastic.co/t/unable-to-install-logstash-input-eventlog-plugin-windows-event-viewer-logs/102388/2 "2017-10-01T21:33:58Z")

</div>

I can't help with the error, sorry, but as an alternative what about using Winlogbeat?

---

<div class="post-metadata">

**Author:** ![scch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/scch/32/25504_2.png) [@scch](https://discuss.elastic.co/u/scch)\
**Post date:** [October 1, 2017, 9:45pm UTC](https://discuss.elastic.co/t/unable-to-install-logstash-input-eventlog-plugin-windows-event-viewer-logs/102388/3 "2017-10-01T21:45:18Z")

</div>

Hey Mark thanks for replying

Currently I have logs available in CSV.. XML ..EVTX format... I have tried with CSV filter however looks like not a very good option for windows logs ...because it contain valuable in formation in long messages..

currently I am exploring XML filter and, eventlog plugin(which looks very simple to implement)

not sure if I get permission to install winlogbeat... are u experienced in installing winlogbeat.

---

<div class="post-metadata">

**Author:** ![scch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/scch/32/25504_2.png) [@scch](https://discuss.elastic.co/u/scch)\
**Post date:** [October 1, 2017, 9:46pm UTC](https://discuss.elastic.co/t/unable-to-install-logstash-input-eventlog-plugin-windows-event-viewer-logs/102388/4 "2017-10-01T21:46:44Z")

</div>

I mean how's you experience with winlogbeat.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [October 1, 2017, 9:52pm UTC](https://discuss.elastic.co/t/unable-to-install-logstash-input-eventlog-plugin-windows-event-viewer-logs/102388/5 "2017-10-01T21:52:50Z")

</div>

It's pretty easy to install and get working, check out [https://www.elastic.co/guide/en/beats/winlogbeat/current/winlogbeat-getting-started.html](https://www.elastic.co/guide/en/beats/winlogbeat/current/winlogbeat-getting-started.html)

---

<div class="post-metadata">

**Author:** ![scch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/scch/32/25504_2.png) [@scch](https://discuss.elastic.co/u/scch)\
**Post date:** [October 3, 2017, 12:38pm UTC](https://discuss.elastic.co/t/unable-to-install-logstash-input-eventlog-plugin-windows-event-viewer-logs/102388/6 "2017-10-03T12:38:26Z")

</div>

I trying to load winlogbeat however unable to start service and got below error.

PS C:\Program Files\winlogbeat\> .\winlogbeat.exe -c .\winlogbeat.yml -configtest -e  
.\winlogbeat.exe : 2017/10/03 12:33:22.287733 metrics.go:23: INFO Metrics logging every 30s  
At line:1 char:2

- .\winlogbeat.exe -c .\winlogbeat.yml -configtest -e
- 

```auto
 + CategoryInfo : NotSpecified: (2017/10/03 12:3...gging every 30s:String) [], RemoteException
 + FullyQualifiedErrorId : NativeCommandError

```

2017/10/03 12:33:22.287733 beat.go:297: INFO Home path: [C:\Program Files\winlogbeat] Config path: [C:\Program Files\winlogbeat] Data path: [C:\Program Files\winlogbeat\data] Logs  
path: [C:\Program Files\winlogbeat\logs]  
2017/10/03 12:33:22.289736 beat.go:192: INFO Setup Beat: winlogbeat; Version: 5.6.2  
2017/10/03 12:33:22.289736 output.go:258: INFO Loading template enabled. Reading template file: C:\Program Files\winlogbeat\winlogbeat.template.json  
2017/10/03 12:33:22.290736 output.go:269: INFO Loading template enabled for Elasticsearch 2.x. Reading template file: C:\Program Files\winlogbeat\winlogbeat.template-es2x.json  
2017/10/03 12:33:22.290736 output.go:281: INFO Loading template enabled for Elasticsearch 6.x. Reading template file: C:\Program Files\winlogbeat\winlogbeat.template-es6x.json  
2017/10/03 12:33:22.290736 client.go:128: INFO Elasticsearch url: [http://XXXXXXX:9200](http://XXXXXXX:9200)  
2017/10/03 12:33:22.290736 outputs.go:108: INFO Activated elasticsearch as output plugin.  
2017/10/03 12:33:22.290736 publish.go:300: INFO Publisher name: XXXXXXX028s  
2017/10/03 12:33:22.293734 async.go:63: INFO Flush Interval set to: 1s  
2017/10/03 12:33:22.293734 async.go:64: INFO Max Bulk Size set to: 50  
2017/10/03 12:33:22.293734 beat.go:346: CRIT Exiting: Error reading configuration file. 1 error: Invalid top-level key 'template' found. Valid keys are bulk\_queue\_size, dashboards,  
fields, fields\_under\_root, geoip, logging, max\_procs, name, output, path, processors, queue\_size, refresh\_topology\_freq, tags, topology\_expire, winlogbeat accessing config  
Exiting: Error reading configuration file. 1 error: Invalid top-level key 'template' found. Valid keys are bulk\_queue\_size, dashboards, fields, fields\_under\_root, geoip, logging,  
max\_procs, name, output, path, processors, queue\_size, refresh\_topology\_freq, tags, topology\_expire, winlogbeat accessing config

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [October 3, 2017, 10:28pm UTC](https://discuss.elastic.co/t/unable-to-install-logstash-input-eventlog-plugin-windows-event-viewer-logs/102388/7 "2017-10-03T22:28:23Z")

</div>

Please post your config, make sure to format it with the `</>` button so it is readable.

---

<div class="post-metadata">

**Author:** ![scch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/scch/32/25504_2.png) [@scch](https://discuss.elastic.co/u/scch)\
**Post date:** [October 4, 2017, 5:53pm UTC](https://discuss.elastic.co/t/unable-to-install-logstash-input-eventlog-plugin-windows-event-viewer-logs/102388/8 "2017-10-04T17:53:36Z")

</div>

Hi Mark, I was able to push windows logs to logstash and then to Elastic search and Kibana.. 😀

currently working on to create dashboard in kibana  
will look in to above errors in coming week.

thanks...

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 1, 2017, 5:53pm UTC](https://discuss.elastic.co/t/unable-to-install-logstash-input-eventlog-plugin-windows-event-viewer-logs/102388/9 "2017-11-01T17:53:38Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
