I'm new to the ELK Stack, and I'm traing to make a lab environment to show to my employeer the beneficts of use this technology.
I'm already installed ElasticSearch, Kibana and Logstash in a CentOS 7 Server.
Now I'm trying to configure WinLogbeat on a Windows Server 2012 R2 Server, to ship the logs to Logstash.
I configured the file winlogbeat.yml with this parameters:
- name: Application
- name: Security
- name: System
I configured a certificate in the Logstash Input, so I copied the certificate to Winlogbeat (I already tried to not use the certificate too)
tls: certificate_authorities: C:\Program Files\winlogbeat\logstash-forwarder.crt
rotateeverybytes: 10485760 # = 10MB
When I try to run the winlogbeat.exe executable as a service, it fails. When I try to run it from command line, I obtain this answer:
C:\Program Files\Winlogbeat>winlogbeat.exe -c winlogbeat.yml
This version of C:\Program Files\Winlogbeat\winlogbeat.exe is not compatible with the version of Windows you're running. Check your computer's system information and then contact the software publisher.
If I review the Event Viewer of Windows, I see:
Source: Application\Wow64 Emulation Layer
Details: The program or feature "??\C:\Program Files\Winlogbeat\winlogbeat.exe" cannot start or run due to incompatibity with 64-bit versions of Windows. Please contact the software vendor to ask if a 64-bit Windows compatible version is available.
I tried WinLogbeat in another Windows Server, 2008 R2, with the same result that I'm showing in this post.
Can you help me? What I'm doing grong?
Thanks in advance.