# Winlogbeat and Scheduled Task Logs (or others)

**URL:** <https://discuss.elastic.co/t/winlogbeat-and-scheduled-task-logs-or-others/136517>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [June 19, 2018, 2:58pm UTC](https://discuss.elastic.co/t/winlogbeat-and-scheduled-task-logs-or-others/136517 "2018-06-19T14:58:13Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![wyliebsd](https://avatars.discourse-cdn.com/v4/letter/w/7bcc69/32.png) [@wyliebsd](https://discuss.elastic.co/u/wyliebsd)\
**Post date:** [June 19, 2018, 2:58pm UTC](https://discuss.elastic.co/t/winlogbeat-and-scheduled-task-logs-or-others/136517/1 "2018-06-19T14:58:13Z")

</div>

Could someone possibly assist me in capturing Schedule Task logs with Winlogbeat?

Right now my config is like this:

winlogbeat.event\_logs:  
- name: Application  
ignore\_older: 72h  
- name: Security  
- name: System  
- name: "Windows Powershell"  
- name: Microsoft/Windows/TaskScheduler/Operational

I have tried wrapping in quotes like i did with with the Powershell log but it doesn't seem to make a difference... If someone could help me with the proper syntax for how to do this I would be very greatful.

Thanks in advance!

-Wylie

---

<div class="post-metadata">

**Author:** ![wyliebsd](https://avatars.discourse-cdn.com/v4/letter/w/7bcc69/32.png) [@wyliebsd](https://discuss.elastic.co/u/wyliebsd)\
**Post date:** [June 19, 2018, 3:30pm UTC](https://discuss.elastic.co/t/winlogbeat-and-scheduled-task-logs-or-others/136517/2 "2018-06-19T15:30:18Z")

</div>

I also tried: Microsoft-Windows-TaskScheduler/Operational - can't see any logs tho.

---

<div class="post-metadata">

**Author:** ![wyliebsd](https://avatars.discourse-cdn.com/v4/letter/w/7bcc69/32.png) [@wyliebsd](https://discuss.elastic.co/u/wyliebsd)\
**Post date:** [June 19, 2018, 4:24pm UTC](https://discuss.elastic.co/t/winlogbeat-and-scheduled-task-logs-or-others/136517/3 "2018-06-19T16:24:22Z")

</div>

Got it to work with: - name: "Mirosoft-Windows-TaskScheduler/Operational"

Please close this thread!

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [June 19, 2018, 4:25pm UTC](https://discuss.elastic.co/t/winlogbeat-and-scheduled-task-logs-or-others/136517/4 "2018-06-19T16:25:13Z")

</div>

I was going to have you run

`PS C:\> Get-WinEvent -ListLog * | Format-List -Property LogName`

to check the name.

Glad you fixed it.

Reference: [https://www.elastic.co/guide/en/beats/winlogbeat/current/configuration-winlogbeat-options.html#configuration-winlogbeat-options-event\_logs-name](https://www.elastic.co/guide/en/beats/winlogbeat/current/configuration-winlogbeat-options.html#configuration-winlogbeat-options-event_logs-name)

---

<div class="post-metadata">

**Author:** ![wyliebsd](https://avatars.discourse-cdn.com/v4/letter/w/7bcc69/32.png) [@wyliebsd](https://discuss.elastic.co/u/wyliebsd)\
**Post date:** [June 19, 2018, 4:25pm UTC](https://discuss.elastic.co/t/winlogbeat-and-scheduled-task-logs-or-others/136517/5 "2018-06-19T16:25:41Z")

</div>

Will note that for later cases! Thanks a bunch Andrew!!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 17, 2018, 4:25pm UTC](https://discuss.elastic.co/t/winlogbeat-and-scheduled-task-logs-or-others/136517/6 "2018-07-17T16:25:42Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
