# Windows NPS Logs

**URL:** <https://discuss.elastic.co/t/windows-nps-logs/289115>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [November 13, 2021, 10:20am UTC](https://discuss.elastic.co/t/windows-nps-logs/289115 "2021-11-13T10:20:56Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![VamPikmin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vampikmin/32/22367_2.png) [@VamPikmin](https://discuss.elastic.co/u/VamPikmin)\
**Post date:** [November 13, 2021, 10:20am UTC](https://discuss.elastic.co/t/windows-nps-logs/289115/1 "2021-11-13T10:20:57Z")

</div>

Hello everyone,

I've been looking for a filebeat module for NPS Logs but there doesn't appear to be one available.

What are my options here?

I have winlogbeat which can get stuff from event log but in C:\Windows\Logs there are much more detailed logs files

Filebeat is the way to go here?

Thanks

---

<div class="post-metadata">

**Author:** ![legoguy1000](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/legoguy1000/32/54301_2.png) [@legoguy1000](https://discuss.elastic.co/u/legoguy1000)\
**Post date:** [November 13, 2021, 5:24pm UTC](https://discuss.elastic.co/t/windows-nps-logs/289115/2 "2021-11-13T17:24:07Z")

</div>

If they are plain text log files then yes, Filebeat is the way to go. Can you post some sample logs?

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [November 13, 2021, 9:22pm UTC](https://discuss.elastic.co/t/windows-nps-logs/289115/3 "2021-11-13T21:22:31Z")

</div>

Or the new Elastic Agent 🙂

---

<div class="post-metadata">

**Author:** ![VamPikmin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vampikmin/32/22367_2.png) [@VamPikmin](https://discuss.elastic.co/u/VamPikmin)\
**Post date:** [November 14, 2021, 4:46am UTC](https://discuss.elastic.co/t/windows-nps-logs/289115/4 "2021-11-14T04:46:20Z")

</div>

Thanks for your replies 🙂

I capture event log 6272 and 6273 with winlogbeat

Sure @legoguy1000

```auto
<Event><Timestamp data_type="4">11/12/2021 09:13:09.669</Timestamp><Computer-Name data_type="1">SPDC2</Computer-Name><Event-Source data_type="1">IAS</Event-Source><Acct-Status-Type data_type="0">2</Acct-Status-Type><NAS-IP-Address data_type="3">192.168.6.2</NAS-IP-Address><User-Name data_type="1">host/device.domain.local</User-Name><NAS-Port data_type="0">0</NAS-Port><NAS-Port-Type data_type="0">19</NAS-Port-Type><Calling-Station-Id data_type="1">xxxx18d2b53b</Calling-Station-Id><Called-Station-Id data_type="1">xxxx12cd9d2a</Called-Station-Id><Framed-IP-Address data_type="3">192.168.1.12</Framed-IP-Address><Acct-Multi-Session-Id data_type="1">xxx18D2B53B-1636662020</Acct-Multi-Session-Id><Acct-Session-Id data_type="1">348A1259D2B2-18CC18D2B53B-618D9548-E2ABB</Acct-Session-Id><Acct-Delay-Time data_type="0">0</Acct-Delay-Time><Vendor-Specific data_type="2">000039E70508454357494649</Vendor-Specific><Vendor-Specific data_type="2">000039E706124450204C6561726E20496E6F76617465</Vendor-Specific><Vendor-Specific data_type="2">000039E702060000005C</Vendor-Specific><Class data_type="1">311 1 192.168.101.14 11/01/2021 23:33:08 418818</Class><Vendor-Specific data_type="2">000039E70C0857696E203130</Vendor-Specific><Acct-Input-Octets data_type="0">35368</Acct-Input-Octets><Acct-Output-Octets data_type="0">2632367</Acct-Output-Octets><Acct-Input-Packets data_type="0">916</Acct-Input-Packets><Acct-Output-Packets data_type="0">4247</Acct-Output-Packets><Acct-Input-Gigawords data_type="0">0</Acct-Input-Gigawords><Acct-Output-Gigawords data_type="0">0</Acct-Output-Gigawords><Acct-Terminate-Cause data_type="0">3</Acct-Terminate-Cause><Acct-Session-Time data_type="0">45</Acct-Session-Time><Service-Type data_type="0">1</Service-Type><NAS-Identifier data_type="1">ECWIFI</NAS-Identifier><Client-IP-Address data_type="3">192.168.6.72</Client-IP-Address><Client-Vendor data_type="0">0</Client-Vendor><Client-Friendly-Name data_type="1">ArubaAP</Client-Friendly-Name><Proxy-Policy-Name data_type="1">ArubaAP</Proxy-Policy-Name><Packet-Type data_type="0">4</Packet-Type><Reason-Code data_type="0">0</Reason-Code></Event>

```

@stephenb  
Are you advising users to ditch filebeat and winlogbeat in favor of elastic agent?

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [November 14, 2021, 6:27am UTC](https://discuss.elastic.co/t/windows-nps-logs/289115/5 "2021-11-14T06:27:25Z")

</div>

You can compare the capabilities here

> **[Beats and Elastic Agent capabilities | Fleet and Elastic Agent Guide \[7.15\] |...](https://www.elastic.co/guide/en/fleet/current/beats-agent-comparison.html)**

Agent supports both windows and log input.

But I think perhaps if you want to decode XML you will still need to use filebeat with the xml\_decode processor

> **[Decode XML | Filebeat Reference \[7.15\] | Elastic](https://www.elastic.co/guide/en/beats/filebeat/current/decode-xml.html)**

Unless you can get to that via windows integration.

---

<div class="post-metadata">

**Author:** ![VamPikmin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vampikmin/32/22367_2.png) [@VamPikmin](https://discuss.elastic.co/u/VamPikmin)\
**Post date:** [November 14, 2021, 7:39am UTC](https://discuss.elastic.co/t/windows-nps-logs/289115/6 "2021-11-14T07:39:06Z")

</div>

Thanks stephenb

I guess I have a lot of reading in front of me.

---

<div class="post-metadata">

**Author:** ![VamPikmin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vampikmin/32/22367_2.png) [@VamPikmin](https://discuss.elastic.co/u/VamPikmin)\
**Post date:** [November 14, 2021, 11:36pm UTC](https://discuss.elastic.co/t/windows-nps-logs/289115/7 "2021-11-14T23:36:58Z")

</div>

Sorry, I have one more question if that's okay

If these logs already have a timestamp how do I force filebeat to use it instead of the @timestamp field?

message:

```auto
"NDDC2","IAS",12/01/2020,09:24:02,11,,"domain.local/DOMAIN/Students BYOD/2023/Name <mark>Surname</mark>",,,,,,,,0,"192.168.131.31","Hi6... (OUTPUT Truncated)

```

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [November 14, 2021, 11:46pm UTC](https://discuss.elastic.co/t/windows-nps-logs/289115/8 "2021-11-14T23:46:33Z")

</div>

You could try the timestamp processor

> **[Timestamp | Filebeat Reference \[7.15\] | Elastic](https://www.elastic.co/guide/en/beats/filebeat/current/processor-timestamp.html)**

Or set that in your ingest pipeline if you build one to parse those logs.

---

<div class="post-metadata">

**Author:** ![VamPikmin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vampikmin/32/22367_2.png) [@VamPikmin](https://discuss.elastic.co/u/VamPikmin)\
**Post date:** [November 15, 2021, 7:51am UTC](https://discuss.elastic.co/t/windows-nps-logs/289115/9 "2021-11-15T07:51:16Z")

</div>

Thanks stephenb

If I'm getting this right, I can't use the timestamp processor unless I create a custom pipeline first or decode the xml, currently all I get from filebeat output is the message, no fields are parsed, so I can't specify a (timestamp) field to parse and delete.

I just have to work out how to create this pipeline or how to decode 😕

Adding the following to the filebeat.yml processors section doesn't seem to work

```auto
 - decode_xml:
      field: message
      target_field: "xml"
      overwrite_keys: true
      ignore_missing: true
      ignore_failure: true

```

Sorry stephenb, is this doable from filebeat.yml or do I need to send to logstash first

---

<div class="post-metadata">

**Author:** ![legoguy1000](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/legoguy1000/32/54301_2.png) [@legoguy1000](https://discuss.elastic.co/u/legoguy1000)\
**Post date:** [November 15, 2021, 12:08pm UTC](https://discuss.elastic.co/t/windows-nps-logs/289115/10 "2021-11-15T12:08:33Z")

</div>

U should be able to use Filebeat processors or logstash to parse xml and/or Elasticsearch ingest pipeline to manipulate the data. Elasticsearch doesn't have a xml processor which is why that had to be done in Filebeat or logstash. Everything else could be done in which ever u prefer.

---

<div class="post-metadata">

**Author:** ![VamPikmin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vampikmin/32/22367_2.png) [@VamPikmin](https://discuss.elastic.co/u/VamPikmin)\
**Post date:** [November 17, 2021, 7:18am UTC](https://discuss.elastic.co/t/windows-nps-logs/289115/11 "2021-11-17T07:18:57Z")

</div>

I was going insane thinking xml decode wasn't working but it turns out the old logs were not in XML format

So before the upgrade the logs were in a ODBC (Legacy) format  
and the new (XML) are the DTS Compliant format

Thank you both for your help, so many options to take now

I've also found this for logstash

> <https://gist.github.com/joaociocca/f3a00b509766f5d4b2aa8aed6b6123a9>

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 15, 2021, 9:18am UTC](https://discuss.elastic.co/t/windows-nps-logs/289115/12 "2021-12-15T09:18:57Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
