Windows log forwarding using filebeat


#1

hi everyone
I am kind of new to ELK.
I am using filebeat to send huge numbers of logs from log servers to logstash machines.
I need to know as to how to forward windows audit logs, event logs IIS logs to the server?
What changes should be made to the config file of filebeat?


(Magnus Bäck) #2

For Windows event logs use Winlogbeat, not Filebeat.


#3

thanks magnus for replying quickly

but the problem is that i cant use winlogbeat as i am supposed to be using filebeat.
is it possible to forward the windows logs using filebeat??


(Magnus Bäck) #4

but the problem is that i cant use winlogbeat as i am supposed to be using filebeat.

Filebeat is the wrong tool for Windows event logs as they are binary files.

is it possible to forward the windows logs using filebeat??

No.


#5

thanks

so Will I be able to forward IIS logs using Winlogbeat?


(Magnus Bäck) #6

Aren't they plain text? If so you should use Filebeat.


#7

thanks

Winlogbeat any tutorial available?


(Magnus Bäck) #8

Is https://www.elastic.co/guide/en/beats/winlogbeat/current/winlogbeat-getting-started.html unclear or insufficient?

Configuration-wise Winlogbeat is very similar to Filebeat.


#9

i guess there wont be an issue to run both filebeat and winlogbeat in the same machine?


(Magnus Bäck) #10

No, of course not.


#11

thanks


(system) #12

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.