# Windows Mass Beats Deployment

**URL:** <https://discuss.elastic.co/t/windows-mass-beats-deployment/322055>\
**Category:** Beats\
**Tags:** beats-module\
**Created:** [December 27, 2022, 8:24pm UTC](https://discuss.elastic.co/t/windows-mass-beats-deployment/322055 "2022-12-27T20:24:11Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Nathan.Arnall](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nathan.arnall/32/115419_2.png) [@Nathan.Arnall](https://discuss.elastic.co/u/Nathan.Arnall)\
**Post date:** [December 27, 2022, 8:24pm UTC](https://discuss.elastic.co/t/windows-mass-beats-deployment/322055/1 "2022-12-27T20:24:11Z")

</div>

Powershell script for deploying beats modules. Can be used with group policy.  
Hopefully this can be of use to anyone else starting out with the ELK stack.

```auto
$beats = "Metricbeat", "Heartbeat", "Auditbeat", "Winlogbeat", "Packetbeat"
# Path to remote location containing beats folders with all files inside. File path can be a network share such as \\server\beatsfolder
# Download your files from https://www.elastic.co/downloads/beats/ as Windows Zip files and extract the folders and name them
# Metricbeat, Heartbeat, Auditbeat, Winlogbeat, Packetbeat accordingly. Place these folder in the same directory in the remote location.
# This will copy each folder into the client's Program Files directory.
# Replace/Modify the *beat.yml file with the config you need.
$beatslocation = "<remote file location here>"
foreach ($beat in $beats){
$beatlower = $beat.ToLower()
    if ((Test-Path -Path "C:\Program Files\$beat\") -eq $false){
        # Pull all files from directory if path does not exist
        copy "$beatslocation\$beat\" -Recurse "C:\Program Files\$beat\" -Force
        & "C:\Program Files\$beat\install-service-$beatlower.ps1"
        Start-Service $beat
    }
    else
    {
        # Update Config if path exists and restart service. Packetbeat has an issue where it does not properly
        # stop/restart, so it kills the process then restarts it.
        copy "$beatslocation\$beat\$beatlower.yml" "C:\Program Files\$beat\$beatlower.yml" -Force
        if ($beat -eq "Packetbeat"){
            if ((Get-Service | Select-Object name) -contains $beatlower) {
                Get-Service | where name -eq $beatlower | kill -Force
                Start-Service $beatlower
            }
            else {
                Start-Service $beatlower
            }
        }
        else {
            Restart-Service $beat
        }
    }
}

```

---

<div class="post-metadata">

**Author:** ![Nathan.Arnall](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nathan.arnall/32/115419_2.png) [@Nathan.Arnall](https://discuss.elastic.co/u/Nathan.Arnall)\
**Post date:** [December 30, 2022, 11:58pm UTC](https://discuss.elastic.co/t/windows-mass-beats-deployment/322055/2 "2022-12-30T23:58:40Z")

</div>

Updated for a clean uninstall /reinstall

```auto
$beats = "Auditbeat", "Filebeat", "Heartbeat", "Metricbeat", "Packetbeat", "Winlogbeat"
$beatslocation = "<remote file location here>"
foreach ($beat in $beats) {
    $beatlower = $beat.ToLower()
#Stop service and wipe path
    if ((Test-Path -Path "C:\Program Files\$beat\") -eq $true) {
        if ((Get-Service -Name "$beat" -ErrorAction SilentlyContinue) -ne $null) {
            Write-Host "$beat Service found. Stopping service."
            #Force Packetbeat to stop
            if ($beat -eq "Packetbeat") {
                Get-Service | where name -eq $beatlower | kill -Force -erroraction SilentlyContinue
            }
            else {
                Stop-Service $beat
            }
        }
        Write-Host "Removing Program Files for $beat"
        Remove-Item "C:\Program Files\$beat" -Recurse
    }
    if ($beat -eq "Packetbeat") {
        if ((Test-Path -Path "C:\Program Files\Npcap\") -eq $false) {
            Write-Host "Npcap not installed. Running installer."
            Unblock-File -Path "C:\Program Files\$beat\install-service-$beatlower.ps1"
            & "C:\Program Files\$beat\install-service-$beatlower.ps1"
            Unblock-File -Path "$beatslocation\Npcap\npcap-1.72.exe"
            & "$beatslocation\Npcap\npcap-1.72.exe"
        Read-Host "Press enter when the installer is finished: "
        }
        else {
            Write-Host "Npcap already installed. Skipping installer."
        }
    }
#Create path
    Write-Host "$beat is not installed. Copying files."
    copy "$beatslocation\$beat\" -Recurse "C:\Program Files\$beat\" -Force
#Install service and start service
        Unblock-File -Path "C:\Program Files\$beat\install-service-$beatlower.ps1"
        & "C:\Program Files\$beat\install-service-$beatlower.ps1"
    Start-Service $beat
}

```

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [December 31, 2022, 12:33am UTC](https://discuss.elastic.co/t/windows-mass-beats-deployment/322055/3 "2022-12-31T00:33:17Z")

</div>

@Nathan.Arnall Welcome to the community and thanks for Sharing.  
I updated the Title so perhaps people searching for Windows can find easier!

---

<div class="post-metadata">

**Author:** ![Nathan.Arnall](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nathan.arnall/32/115419_2.png) [@Nathan.Arnall](https://discuss.elastic.co/u/Nathan.Arnall)\
**Post date:** [December 31, 2022, 12:37am UTC](https://discuss.elastic.co/t/windows-mass-beats-deployment/322055/4 "2022-12-31T00:37:08Z")

</div>

Thanks!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 28, 2023, 2:38am UTC](https://discuss.elastic.co/t/windows-mass-beats-deployment/322055/5 "2023-01-28T02:38:08Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
