# Usage of Winlogbeat on Linux / Parse plaintext windows events files

**URL:** <https://discuss.elastic.co/t/usage-of-winlogbeat-on-linux-parse-plaintext-windows-events-files/270113>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [April 14, 2021, 1:05pm UTC](https://discuss.elastic.co/t/usage-of-winlogbeat-on-linux-parse-plaintext-windows-events-files/270113 "2021-04-14T13:05:50Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![GeorgeGkinis](https://avatars.discourse-cdn.com/v4/letter/g/ecc23a/32.png) [@GeorgeGkinis](https://discuss.elastic.co/u/GeorgeGkinis)\
**Post date:** [April 14, 2021, 1:05pm UTC](https://discuss.elastic.co/t/usage-of-winlogbeat-on-linux-parse-plaintext-windows-events-files/270113/1 "2021-04-14T13:05:50Z")

</div>

We have the need to run winlogbeat on Linux.  
I see that there are no precompiled binaries for Linux which is somewhat understandable.

In our usecase winlog events are transported via **syslog** to a **linux VM**.  
There parsing happens with **filebeat** for many types of **plaintext** logs.

Among those logs are the windows events logs and was hoping to be able to parse them with winlogbeat.  
Another issue is that the logs are **plaintext** instead of \ ***.evtx** files 😕

I was thinking of modifying the **winlogbeat-security.js, winlogbeat-powershell.js** and **winlogbeat-sysmon.js** and use those scripts with **filebeat**.

In other words : reuse/modify your wonderfull JS code from the **winlogbeat modules** and create **filebeat modules.**

Any technical difficulties that I might encounter?  
Is this unfeasible maybe?

Any suggestions?

---

<div class="post-metadata">

**Author:** ![Marius\_Iversen](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marius_iversen/32/68988_2.png) [@Marius\_Iversen](https://discuss.elastic.co/u/Marius_Iversen)\
**Post date:** [April 14, 2021, 2:52pm UTC](https://discuss.elastic.co/t/usage-of-winlogbeat-on-linux-parse-plaintext-windows-events-files/270113/2 "2021-04-14T14:52:13Z")

</div>

Hello @GeorgeGkinis 🙂

Out of curiosity, how is the events from windows transferred through syslog? Is it maybe a local agent like solarwinds or nxlog?

I would say that while filebeat is your best bet indeed, there might be some better approaches, and it kinda depends on the format of these syslog messages, so before I can help you any further, would you be able to provide a line or two from the file itself? Feel free to obfuscate any sensitive fields, as long as it keeps the format 100% the same 🙂

The reason is that some windows syslog agents forwards the whole XML, while others just picks parts of the message and send it through a unformatted syslog message. So for example if it was raw XML, we have a new XML processor in filebeat that would help you a lot 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 12, 2021, 4:52pm UTC](https://discuss.elastic.co/t/usage-of-winlogbeat-on-linux-parse-plaintext-windows-events-files/270113/3 "2021-05-12T16:52:36Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
