# Windows Logs via Elastic Agent

**URL:** <https://discuss.elastic.co/t/windows-logs-via-elastic-agent/382350>\
**Category:** Elastic Agent\
**Created:** [October 1, 2025, 11:51am UTC](https://discuss.elastic.co/t/windows-logs-via-elastic-agent/382350 "2025-10-01T11:51:49Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Sam11](https://avatars.discourse-cdn.com/v4/letter/s/c6cbf5/32.png) [@Sam11](https://discuss.elastic.co/u/Sam11)\
**Post date:** [October 1, 2025, 11:51am UTC](https://discuss.elastic.co/t/windows-logs-via-elastic-agent/382350/1 "2025-10-01T11:51:49Z")

</div>

Hello,

I am facing an issue with Windows logs when using Elastic Agent: the logs are not being sent to Kibana. However, Winlogbeat works correctly and is able to send the logs.

This is my elastic-agent configuration

```auto
agent:
  logging:
    level: debug
  monitoring:
    enabled: false
    logs: false
    metrics: false
outputs:
  default:
    type: logstash
    hosts: ["xxxxxx:5044"]
    ssl:
      enabled: true
      certificate_authorities:
        - "C:/Program Files/Elastic/Agent/certs/ca.crt"

```

```auto
inputs:
type: winlog
id: winlog-security
use_output: default
data_stream:
dataset: windows.security
namespace: default
name: Security
ignore_older: 72h
api: eventlog
processors:
  -add_fields:
     target: ""
     fields:
       app_type: "windows-ad"
  -add_host_metadata: {}
  - add_process_metadata: {}
    # event_id: 4624,4625,4768,4769,4776,4740  

  - type: winlog
    id: winlog-application
    use_output: default
    data_stream:
      dataset: windows.application
      namespace: default
    name: Application
    ignore_older: 24h
    api: eventlog
    processors:
      - add_fields:
          target: ""
          fields:
            app_type: "windows-ad"
      - add_host_metadata: {}
      - add_process_metadata: {}

```

Is there Any suggestion or solution please?

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [October 1, 2025, 1:02pm UTC](https://discuss.elastic.co/t/windows-logs-via-elastic-agent/382350/2 "2025-10-01T13:02:13Z")

</div>

What does your Logstash configuration looks like?

Your output is logstash, so you need to check if the configuration is correct and if there is any error, check the Logstash logs.

I'm also not sure if the indentation of your yaml file is correct:

> [@Sam11](#):
>
> ```auto
> inputs:
> type: winlog
> id: winlog-security
> use_output: default
> data_stream:
> dataset: windows.security
> namespace: default
> name: Security
> ignore_older: 72h
> api: eventlog
> processors:
> -add_fields:
> target: ""
> fields:
> app_type: "windows-ad"
> -add_host_metadata: {}
> - add_process_metadata: {}
> # event_id: 4624,4625,4768,4769,4776,4740  
> 
> - type: winlog
> id: winlog-application
> use_output: default
> data_stream:
> dataset: windows.application
> namespace: default
> name: Application
> ignore_older: 24h
> api: eventlog
> processors:
> - add_fields:
> target: ""
> fields:
> app_type: "windows-ad"
> - add_host_metadata: {}
> - add_process_metadata: {}
> 
> ```

This does not seems right, is your agent running? What do you have in its log?

---

<div class="post-metadata">

**Author:** ![Sam11](https://avatars.discourse-cdn.com/v4/letter/s/c6cbf5/32.png) [@Sam11](https://discuss.elastic.co/u/Sam11)\
**Post date:** [October 1, 2025, 1:52pm UTC](https://discuss.elastic.co/t/windows-logs-via-elastic-agent/382350/3 "2025-10-01T13:52:46Z")

</div>

Thank you for your response.

The elastic agent is running and its log is clean no error or warning!!

Same is going for the Logstash!!!

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [October 1, 2025, 1:57pm UTC](https://discuss.elastic.co/t/windows-logs-via-elastic-agent/382350/4 "2025-10-01T13:57:30Z")

</div>

You need to share the logstash configuration and the logs as well, it is not possible to provide any insight without this information.

---

<div class="post-metadata">

**Author:** ![Sam11](https://avatars.discourse-cdn.com/v4/letter/s/c6cbf5/32.png) [@Sam11](https://discuss.elastic.co/u/Sam11)\
**Post date:** [October 2, 2025, 7:53am UTC](https://discuss.elastic.co/t/windows-logs-via-elastic-agent/382350/5 "2025-10-02T07:53:06Z")

</div>

The issue is the ELK stack is working just fine, and at the same elastic agent configuration I have put two types of inputs one filestream and the other is winlog the filestream is working and sucessufully reaching kibana while nothing about Windows logs!!

This is my Logstash Configuration

```auto
input {
  beats {
    port => 5044
    add_field => {
      "source_type" => "elastic-agent"
    }
    ssl_enabled => true
    ssl_key => "/distrib/elk/latest/logstash/config/certs/logstash.key"
    ssl_certificate => "/distrib/elk/latest/logstash/config/certs/logstash.crt"
    #ssl_certificate_authorities => ["/distrib/elk/latest/logstash/config/certs/ca.crt"]
    #ssl_verify_mode => "force_peer" 
  }

}

output {
  elasticsearch {
    hosts => ["xxxxxxx:9200"]
    user => "user"
    password => " *************"
    ssl_enabled => true
    ssl_certificate_authorities =>["/distrib/elk/latest/logstash/config/certs/ca.crt"]

    index => "%{[@metadata][alias]}"
  }
}

```

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [October 2, 2025, 12:47pm UTC](https://discuss.elastic.co/t/windows-logs-via-elastic-agent/382350/6 "2025-10-02T12:47:55Z")

</div>

Your logstash configuration is not according with the recommended configuration from the [documentation](https://www.elastic.co/docs/reference/fleet/logstash-output).

First, when using Elastic Agent you should use the `elastic_agent` input, and you need to set `enrich => false` on this input, then you also do not specify an `index` setting in the output, it will write into the data stream, you need to use `data_stream => true` only.

You would need something like this:

```auto
input {
  elastic_agent {
    port => 5044
    enrich => none
    ssl_enabled => true
    ssl_certificate_authorities => ["<ca_path>"]
    ssl_certificate => "<server_cert_path>"
    ssl_key => "<server_cert_key_in_pkcs8>"
    ssl_client_authentication => "required"
  }
}

output {
  elasticsearch {
    hosts => ["http://localhost:9200"]
    data_stream => "true"
    user => "username"
    password => "password"
    data_stream => true
    ssl_enabled => true
    ssl_certificate_authorities => "<elasticsearch_ca_path>"
  }
}

```

This works fine for me with Fleet managed agents, it should work for standalone agents as well.

---

<div class="post-metadata">

**Author:** ![Sam11](https://avatars.discourse-cdn.com/v4/letter/s/c6cbf5/32.png) [@Sam11](https://discuss.elastic.co/u/Sam11)\
**Post date:** [October 2, 2025, 1:00pm UTC](https://discuss.elastic.co/t/windows-logs-via-elastic-agent/382350/7 "2025-10-02T13:00:53Z")

</div>

Thank you.

I will try this and let you know.

---

<div class="post-metadata">

**Author:** ![Sam11](https://avatars.discourse-cdn.com/v4/letter/s/c6cbf5/32.png) [@Sam11](https://discuss.elastic.co/u/Sam11)\
**Post date:** [October 2, 2025, 2:18pm UTC](https://discuss.elastic.co/t/windows-logs-via-elastic-agent/382350/8 "2025-10-02T14:18:19Z")

</div>

When I set the data\_stream to true even yhe filestream inputs are not indexed to Kibana anymore!

What could be the reason?
