# Windows protected event logging format

**URL:** https://discuss.elastic.co/t/windows-protected-event-logging-format/209680
**Category:** Beats
**Tags:** winlogbeat
**Created:** [November 27, 2019, 12:41pm UTC](https://discuss.elastic.co/t/windows-protected-event-logging-format/209680 "2019-11-27T12:41:28Z")
**Posts on this page:** 2
**Page:** 1

<div class="post-metadata">

### Author: ![kinomakino](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kinomakino/32/12614_2.png) [@kinomakino](https://discuss.elastic.co/u/kinomakino)
#### Post date: [November 27, 2019, 12:41pm UTC](https://discuss.elastic.co/t/windows-protected-event-logging-format/209680/1 "2019-11-27T12:41:28Z")

</div>

First of all, thanks for the help.

We are considering using PEL to protect Windows logs and we don't know very well how to do the decryption process to incorporate the logs into ELK using Logstash and winlogbeat.

Thanks for everything.

PEL [https://blogs.technet.microsoft.com/kfalde/2017/05/13/securing-your-powershell-operational-logs/](https://blogs.technet.microsoft.com/kfalde/2017/05/13/securing-your-powershell-operational-logs/)

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [December 25, 2019, 12:41pm UTC](https://discuss.elastic.co/t/windows-protected-event-logging-format/209680/2 "2019-12-25T12:41:46Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
