# Windows Event Log connector with Logstash

**URL:** <https://discuss.elastic.co/t/windows-event-log-connector-with-logstash/353274>\
**Category:** Logstash\
**Tags:** elastic-stack-security\
**Created:** [February 14, 2024, 12:59pm UTC](https://discuss.elastic.co/t/windows-event-log-connector-with-logstash/353274 "2024-02-14T12:59:23Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![RemyB](https://avatars.discourse-cdn.com/v4/letter/r/a87d85/32.png) [@RemyB](https://discuss.elastic.co/u/RemyB)\
**Post date:** [February 14, 2024, 12:59pm UTC](https://discuss.elastic.co/t/windows-event-log-connector-with-logstash/353274/1 "2024-02-14T12:59:23Z")

</div>

Hello all,

I would like to thank you in advance for your time reading my following issue :  
In order to install the windows integrations (Windows Event Logs/Windows) and benefit from the provided visualisations and the rules from Elastic Security, I'm trying to setup the integration by modifying the winlogbeat.yml in the Winlogbeat install directory by adding :

output.elasticsearch:  
hosts: ["\<es\_url\>"]  
username: "elastic"  
password: ""  
setup.kibana:  
host: "\<kibana\_url\>"

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/4/9/495748f35861676a7a049fe351465921fc89fd21.png)

However, we use Logstash between the winlogbeat (installed on WEF) and Elasticsearch and I could not figure out which setup to implement making the log appearing in the stream and from the connector.

Does the setup need to be the same when Logstash is used ? Is it going to duplicate the events by adding output.elasticsearch in the winlogbeat config ?

Thank you in advance for your help on this and sorry if the subject has been treated yet in the portal.

Regards,

Remy

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [February 14, 2024, 1:07pm UTC](https://discuss.elastic.co/t/windows-event-log-connector-with-logstash/353274/2 "2024-02-14T13:07:05Z")

</div>

> [@RemyB](#):
>
> Does the setup need to be the same when Logstash is used ? Is it going to duplicate the events by adding output.elasticsearch in the winlogbeat config ?

All beats only support one output, so if you need Logstash between your beat and Elasticsearch, then you need to configure the Logstash output.

Check this [documentation](https://www.elastic.co/guide/en/beats/winlogbeat/current/logstash-output.html#logstash-output) with the steps to configure the Logstash output.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 13, 2024, 1:07pm UTC](https://discuss.elastic.co/t/windows-event-log-connector-with-logstash/353274/3 "2024-03-13T13:07:16Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
