# Winlogbeat and Reading Log Files

**URL:** <https://discuss.elastic.co/t/winlogbeat-and-reading-log-files/42035>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [February 17, 2016, 2:57pm UTC](https://discuss.elastic.co/t/winlogbeat-and-reading-log-files/42035 "2016-02-17T14:57:18Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Franck\_Strohmenger](https://avatars.discourse-cdn.com/v4/letter/f/e79b87/32.png) [@Franck\_Strohmenger](https://discuss.elastic.co/u/Franck_Strohmenger)\
**Post date:** [February 17, 2016, 2:57pm UTC](https://discuss.elastic.co/t/winlogbeat-and-reading-log-files/42035/1 "2016-02-17T14:57:18Z")

</div>

Hello,  
I'm working on a ELK server to monitor a windows server 2008 R2 farm. I installed Winlogbeat agent on my client servers and it works pretty good with windows event logs.  
I want to go further and ship logs from log files (for example C:\Windows\WindowsUpdate.log) to logstash.  
Is it possible to ship other log than windows event logs with winlogbeat?  
Thanks in advance and sorry for my english 😛  
Franck

---

<div class="post-metadata">

**Author:** ![marke72](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marke72/32/10832_2.png) [@marke72](https://discuss.elastic.co/u/marke72)\
**Post date:** [February 17, 2016, 6:43pm UTC](https://discuss.elastic.co/t/winlogbeat-and-reading-log-files/42035/2 "2016-02-17T18:43:40Z")

</div>

You could probably use Filebeat for something like that. [https://www.elastic.co/products/beats/filebeat](https://www.elastic.co/products/beats/filebeat)

---

<div class="post-metadata">

**Author:** ![Franck\_Strohmenger](https://avatars.discourse-cdn.com/v4/letter/f/e79b87/32.png) [@Franck\_Strohmenger](https://discuss.elastic.co/u/Franck_Strohmenger)\
**Post date:** [February 17, 2016, 8:53pm UTC](https://discuss.elastic.co/t/winlogbeat-and-reading-log-files/42035/3 "2016-02-17T20:53:29Z")

</div>

Oh, I thought filebeat not working with windows !  
Have it always worked with?  
I'm sure i've already tried filebeat for windows and been blocked for this reason...  
Whatever, thank you for your answer, i will try this  
Franck

---

<div class="post-metadata">

**Author:** ![Franck\_Strohmenger](https://avatars.discourse-cdn.com/v4/letter/f/e79b87/32.png) [@Franck\_Strohmenger](https://discuss.elastic.co/u/Franck_Strohmenger)\
**Post date:** [February 18, 2016, 1:26pm UTC](https://discuss.elastic.co/t/winlogbeat-and-reading-log-files/42035/4 "2016-02-18T13:26:20Z")

</div>

It works 🙂  
thank you !

---

<div class="post-metadata">

**Author:** ![cciaccio](https://avatars.discourse-cdn.com/v4/letter/c/ccd318/32.png) [@cciaccio](https://discuss.elastic.co/u/cciaccio)\
**Post date:** [March 21, 2016, 8:27pm UTC](https://discuss.elastic.co/t/winlogbeat-and-reading-log-files/42035/5 "2016-03-21T20:27:48Z")

</div>

On all our windows servers we need to read both windows event logs and regular log files. This means we would need to manage two shipping agents on all the windows servers.  
Is there a plan to make Winlogbeat able to read regular log files?  
Thank you

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [April 12, 2016, 1:47pm UTC](https://discuss.elastic.co/t/winlogbeat-and-reading-log-files/42035/6 "2016-04-12T13:47:06Z")

</div>


