# Using Channel Names in Winlogbeat Config

**URL:** <https://discuss.elastic.co/t/using-channel-names-in-winlogbeat-config/44555>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [March 16, 2016, 1:41pm UTC](https://discuss.elastic.co/t/using-channel-names-in-winlogbeat-config/44555 "2016-03-16T13:41:00Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![ArneO](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/arneo/32/7091_2.png) [@ArneO](https://discuss.elastic.co/u/ArneO)\
**Post date:** [March 16, 2016, 1:41pm UTC](https://discuss.elastic.co/t/using-channel-names-in-winlogbeat-config/44555/1 "2016-03-16T13:41:01Z")

</div>

Is it possible to use Winlogbeat for the "Application and Services Log" types in addition to the eventlog?

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [March 16, 2016, 2:05pm UTC](https://discuss.elastic.co/t/using-channel-names-in-winlogbeat-config/44555/2 "2016-03-16T14:05:30Z")

</div>

If by "Application and Services Log" you mean log files, then no. That is what Filebeat does so deploy Filebeat and Winlogbeat.

Similar to [Winlogbeat and Reading Log Files](https://discuss.elastic.co/t/winlogbeat-and-reading-log-files/42035)

---

<div class="post-metadata">

**Author:** ![ArneO](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/arneo/32/7091_2.png) [@ArneO](https://discuss.elastic.co/u/ArneO)\
**Post date:** [March 16, 2016, 2:29pm UTC](https://discuss.elastic.co/t/using-channel-names-in-winlogbeat-config/44555/3 "2016-03-16T14:29:06Z")

</div>

The logs I'm thinking about is list by `Get-WinEvent -ListLog *` using powershell.

In Eventviewer they are listed below the "Windows Logs" which are easily logged by winlogbeat.

The Windows eventlog "Application" are located in %SystemRoot%\System32\Winevt\Logs\Application.evtx  
And one which may be nice to get are the Hardwareevent which are located in %SystemRoot%\System32\Winevt\Logs\HardwareEvents.evtx

I'm not a windows man, but it looks like the "Application and Services Log" use the same framwork for logging as the Eventlogs.

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [March 16, 2016, 3:38pm UTC](https://discuss.elastic.co/t/using-channel-names-in-winlogbeat-config/44555/4 "2016-03-16T15:38:37Z")

</div>

Yes, see the documentation for [`event_logs.name`](https://www.elastic.co/guide/en/beats/winlogbeat/current/configuration-winlogbeat-options.html#configuration-winlogbeat-options-event_logs-name). Also, there's a script [here](https://discuss.elastic.co/t/use-wildcards-in-channels-with-winlogbeat/43367/2) to generate a config file that reads from all channels.

---

<div class="post-metadata">

**Author:** ![ArneO](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/arneo/32/7091_2.png) [@ArneO](https://discuss.elastic.co/u/ArneO)\
**Post date:** [March 17, 2016, 8:02am UTC](https://discuss.elastic.co/t/using-channel-names-in-winlogbeat-config/44555/5 "2016-03-17T08:02:39Z")

</div>

Thanks!

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [April 12, 2016, 1:44pm UTC](https://discuss.elastic.co/t/using-channel-names-in-winlogbeat-config/44555/6 "2016-04-12T13:44:20Z")

</div>


