# Unable to see winlogbeat events

**URL:** <https://discuss.elastic.co/t/unable-to-see-winlogbeat-events/234671>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [May 28, 2020, 6:37am UTC](https://discuss.elastic.co/t/unable-to-see-winlogbeat-events/234671 "2020-05-28T06:37:54Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![nkrshna](https://avatars.discourse-cdn.com/v4/letter/n/96bed5/32.png) [@nkrshna](https://discuss.elastic.co/u/nkrshna)\
**Post date:** [May 28, 2020, 6:37am UTC](https://discuss.elastic.co/t/unable-to-see-winlogbeat-events/234671/1 "2020-05-28T06:37:54Z")

</div>

Hi,

I'm new to Elasticsearch and configured 7 version running on CentOS 7. Trying to configure windows server to send event logs to ESS server but I'm not able to see any events under winlogbeat index pattern.

Below is my winlogbeat.yml file.

```auto
    winlogbeat.event_logs:
      - name: Application
      - name: System
      - name: Security

    setup.template.settings:
      index.number_of_shards: 1

    setup.kibana:
      host: "ESS_IP:5601"

    output.logstash:
      hosts: ["ESS_IP:5044"]

    processors:
      - add_host_metadata: ~
      - add_cloud_metadata: ~
      - add_docker_metadata: ~

```

Please help on this.

---

<div class="post-metadata">

**Author:** ![MarianaD](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marianad/32/42687_2.png) [@MarianaD](https://discuss.elastic.co/u/MarianaD)\
**Post date:** [May 28, 2020, 11:12am UTC](https://discuss.elastic.co/t/unable-to-see-winlogbeat-events/234671/2 "2020-05-28T11:12:51Z")

</div>

hi @nkrshna, you need to configure the `output.elasticsearch` ([https://www.elastic.co/guide/en/beats/winlogbeat/current/elasticsearch-output.html](https://www.elastic.co/guide/en/beats/winlogbeat/current/elasticsearch-output.html)), I see you are sending the events to Logstash instead.

---

<div class="post-metadata">

**Author:** ![nkrshna](https://avatars.discourse-cdn.com/v4/letter/n/96bed5/32.png) [@nkrshna](https://discuss.elastic.co/u/nkrshna)\
**Post date:** [May 28, 2020, 1:11pm UTC](https://discuss.elastic.co/t/unable-to-see-winlogbeat-events/234671/3 "2020-05-28T13:11:38Z")

</div>

@MarianaD Thanks for the reply.

I have made changes as below.

```auto
    winlogbeat.event_logs:
      - name: Application
      - name: System
      - name: Security

    setup.template.settings:
      index.number_of_shards: 1

    setup.kibana:
      host: "ESS_IP:5601"

    output.elasticsearch:
      hosts: ["ESS_IP:9200"]

    processors:
      - add_host_metadata: ~
      - add_cloud_metadata: ~
      - add_docker_metadata: ~

```

I Kibana how can i check the data, completely new to Elasticsearch.

---

<div class="post-metadata">

**Author:** ![MarianaD](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marianad/32/42687_2.png) [@MarianaD](https://discuss.elastic.co/u/MarianaD)\
**Post date:** [May 28, 2020, 1:16pm UTC](https://discuss.elastic.co/t/unable-to-see-winlogbeat-events/234671/4 "2020-05-28T13:16:29Z")

</div>

hi @nkrshna, you can use the Dev Tools console and query for any winlogbeat events:  
[https://www.elastic.co/guide/en/kibana/current/console-kibana.html](https://www.elastic.co/guide/en/kibana/current/console-kibana.html)

```auto
GET winlogbeat*/_search

```

should do the trick.  
I

---

<div class="post-metadata">

**Author:** ![nkrshna](https://avatars.discourse-cdn.com/v4/letter/n/96bed5/32.png) [@nkrshna](https://discuss.elastic.co/u/nkrshna)\
**Post date:** [May 29, 2020, 6:03am UTC](https://discuss.elastic.co/t/unable-to-see-winlogbeat-events/234671/5 "2020-05-29T06:03:43Z")

</div>

Thanks @MarianaD. I have tried the same in Dev tools but got below output. I think there is no data being parsed.

```auto
{
  "took" : 0,
  "timed_out" : false,
  "_shards" : {
    "total" : 0,
    "successful" : 0,
    "skipped" : 0,
    "failed" : 0
  },
  "hits" : {
    "total" : {
      "value" : 0,
      "relation" : "eq"
    },
    "max_score" : 0.0,
    "hits" : []
  }
}

```

---

<div class="post-metadata">

**Author:** ![MarianaD](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marianad/32/42687_2.png) [@MarianaD](https://discuss.elastic.co/u/MarianaD)\
**Post date:** [June 2, 2020, 11:19am UTC](https://discuss.elastic.co/t/unable-to-see-winlogbeat-events/234671/6 "2020-06-02T11:19:51Z")

</div>

hi @nkrshna, can you check the winlogbeat logs and the elasticsearch logs, they will most likely tell you more on the reason. If there is no relevant info in the logs can you enable the debug level and retry.

---

<div class="post-metadata">

**Author:** ![nkrshna](https://avatars.discourse-cdn.com/v4/letter/n/96bed5/32.png) [@nkrshna](https://discuss.elastic.co/u/nkrshna)\
**Post date:** [June 8, 2020, 11:39am UTC](https://discuss.elastic.co/t/unable-to-see-winlogbeat-events/234671/7 "2020-06-08T11:39:29Z")

</div>

Hi @MarianaD i have gone through once again on winlogbeat configuration and i see that error when executed below code in windows systems as administrator in powershell.

```auto
PS > .\winlogbeat.exe setup --index-management -E output.logstash.enabled=false -E 'output.elasticsearch.hosts=["localhost:9200"]'

```

Error message as

```auto
PS C:\Program Files\Winlogbeat> .\winlogbeat.exe setup --index-management -E output.logstash.enabled=false -E 'output.elasticsearch.hosts=["localhost:9200"]'
Exiting: couldn't connect to any of the configured Elasticsearch hosts. Errors: [error connecting to Elasticsearch at http://localhost:9200: Get http://localhost:9200: dial tcp [::1]:9200: connectex: No connection could be made because the target machine actively refused it.]
PS C:\Program Files\Winlogbeat> .\winlogbeat.exe setup --index-management -E output.logstash.enabled=false -E 'output.elasticsearch.hosts=["Elasticsearch_IP:9200"]'
Exiting: couldn't connect to any of the configured Elasticsearch hosts. Errors: [error connecting to Elasticsearch at http://Elasticsearch_IP:9200: Get http://Elasticsearch_IP:9200: dial tcp Elasticsearch_IP:9200: connectex: No connection could be made because the target machine actively refused it.]

```

Can you help further on this ?

---

<div class="post-metadata">

**Author:** ![nkrshna](https://avatars.discourse-cdn.com/v4/letter/n/96bed5/32.png) [@nkrshna](https://discuss.elastic.co/u/nkrshna)\
**Post date:** [July 3, 2020, 5:35pm UTC](https://discuss.elastic.co/t/unable-to-see-winlogbeat-events/234671/8 "2020-07-03T17:35:32Z")

</div>

After setting `network.host: 0.0.0.0` in elasticsearch.yml file and restarting elasticsearch service issue got resolved and Windows events are reflecting in the portal.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 31, 2020, 5:35pm UTC](https://discuss.elastic.co/t/unable-to-see-winlogbeat-events/234671/9 "2020-07-31T17:35:49Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
