# Winlogbeat and Logstash Input Codec

**URL:** <https://discuss.elastic.co/t/winlogbeat-and-logstash-input-codec/42527>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [February 23, 2016, 7:51pm UTC](https://discuss.elastic.co/t/winlogbeat-and-logstash-input-codec/42527 "2016-02-23T19:51:34Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![cord\_thomas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cord_thomas/32/8009_2.png) [@cord\_thomas](https://discuss.elastic.co/u/cord_thomas)\
**Post date:** [February 23, 2016, 7:51pm UTC](https://discuss.elastic.co/t/winlogbeat-and-logstash-input-codec/42527/1 "2016-02-23T19:51:34Z")

</div>

We are evaluating ELK as a distributed monitoring system. I have installed ELK and have some syslogs shipping from various systems.

I have just tried installing winlogbeat 1.1.1 on a Windows 8 VM in Parallels.

Logstash 2.2

I am seeing traffic all the way into the ELK server (via tcpdump) but not getting consistent records - i am seeing this error stanza regularly - seems partial log events are getting passed along. Anything I should set on the client to only send complete records? I don't see anything obvious in the configuration elements.

at [Source: [B@77ae0b1; line: 1, column: 5]\>, :data=\>"The Windows Filtering Platform has permitted a connection.\n\nApplication Information:\n\tProcess ID:\t\t1368\n\tApplication Name:\t\device\harddiskvolume2\windows\system32\svchost.exe\n\nNetwork Information:\n\tDirection:\t\tInbound\n\tSource Address:\t\t239.255.255.250\n\tSource Port:\t\t1900\n\tDestination Address:\t127.0.0.1\n\tDestination Port:\t\t63569\n\tProtocol:\t\t17\n\nFilter Information:\n\tFilter Run-Time ID:\t69068\n\tLayer Name:\t\tReceive/Accept\n\tLayer Run-Time ID:\t44", :level=\>:error}  
**{:timestamp=\>"2016-02-23T11:40:25.248000-0800", :message=\>"JSON parse failure. Falling back to plain-text", :error=\>#\<LogStash::Json::ParserError: Unrecognized token 'The': was expecting ('true', 'false' or 'null')**

**client config:**

```auto
winlogbeat:
  event_logs:
    - name: Application
      ignore_older: 72h 
    - name: Security
    - name: System

output:
  logstash:
    hosts: ["smshepherd01.rand.org:5044"]
    worker: 1
    index: winlogbeat-cthomas

  file:
    path: "C:/Data/winlogbeat"

```

**Server logstash config related to beats**

```auto
input {
  beats {
    port => "5044"
    type => "wincli-log"
    codec => "json"
  }
}

```

output stanza portion:

```auto
  } else if [type] == "wincli-log" {
      elasticsearch {
         hosts => ["logstashserver:9201"]
         index => "journal-%{+YYYY.MM.dd}"
     }
     stdout { codec => rubydebug { metadata => true } }

```

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [February 23, 2016, 11:19pm UTC](https://discuss.elastic.co/t/winlogbeat-and-logstash-input-codec/42527/2 "2016-02-23T23:19:54Z")

</div>

> [@cord\_thomas](#):
>
> codec =\> "json"

Remove the json codec from your Logstash configuration. The `message` field is not JSON, it's the plain text message from the Windows event log record.

---

<div class="post-metadata">

**Author:** ![cord\_thomas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cord_thomas/32/8009_2.png) [@cord\_thomas](https://discuss.elastic.co/u/cord_thomas)\
**Post date:** [February 24, 2016, 12:06am UTC](https://discuss.elastic.co/t/winlogbeat-and-logstash-input-codec/42527/4 "2016-02-24T00:06:14Z")

</div>

Thank you. I will try that.

I am somewhat surprised as in looking at a copy of the log information written locally using the client file stanza it certainly looks and smells like json. linklint says it's json. I am obviously not understanding what is being forwarded by the beat. I am posting another question about the 'type' value i am seeing...

here is an entry redacted a little to protect the ignorant (or innocent):

{"@metadata":{"beat":"winlogbeat-cthomas","type":"wineventlog"},"@timestamp":"2016-02-23T19:31:24.317Z","beat":{"hostname":"thomas-c-pvm","name":"thomas-c-pvm"},"category":"Filtering Platform Connection","computer\_name":"[thomas-c-pvm.company.com](http://thomas-c-pvm.company.com)","count":1,"event\_id":5156,"level":"Information","log\_name":"Security","message":"The Windows Filtering Platform has permitted a connection.\n\nApplication Information:\n\tProcess ID:\t\t4488\n\tApplication Name:\t\device\harddiskvolume2\program files\winlogbeat\winlogbeat.exe\n\nNetwork Information:\n\tDirection:\t\tOutbound\n\tSource Address:\t\t10.211.55.3\n\tSource Port:\t\t50908\n\tDestination Address:\t99.99.99.99\n\tDestination Port:\t\t9999\n\tProtocol:\t\t6\n\nFilter Information:\n\tFilter Run-Time ID:\t69060\n\tLayer Name:\t\tConnect\n\tLayer Run-Time ID:\t48","record\_number":"11936981","source\_name":"Microsoft-Windows-Security-Auditing","type":"wineventlog"}

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [February 24, 2016, 12:28am UTC](https://discuss.elastic.co/t/winlogbeat-and-logstash-input-codec/42527/5 "2016-02-24T00:28:42Z")

</div>

Yes, what you posted is JSON. The beat sends its events a JSON. The input codec you used applies only to the `message` field of that JSON event. This tells Logstash to take the contents of the message field and unmarshal it as JSON.

Take a look at the logstash-input-beats documentation. In particular see the [target\_field\_for\_codec](https://www.elastic.co/guide/en/logstash/current/plugins-inputs-beats.html#plugins-inputs-beats-target_field_for_codec) and [codec](https://www.elastic.co/guide/en/logstash/current/plugins-inputs-beats.html#plugins-inputs-beats-codec) docs.

An example use case for the JSON codec would be if you were reading log lines with Filebeat and each of those lines was a JSON object.

---

<div class="post-metadata">

**Author:** ![cord\_thomas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cord_thomas/32/8009_2.png) [@cord\_thomas](https://discuss.elastic.co/u/cord_thomas)\
**Post date:** [February 24, 2016, 12:30am UTC](https://discuss.elastic.co/t/winlogbeat-and-logstash-input-codec/42527/6 "2016-02-24T00:30:03Z")

</div>

Ahh, that clears up that piece. Thanks!

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [April 12, 2016, 1:39pm UTC](https://discuss.elastic.co/t/winlogbeat-and-logstash-input-codec/42527/7 "2016-04-12T13:39:10Z")

</div>


