# Winlogbeat as a docker sibling/sidecar container

**URL:** <https://discuss.elastic.co/t/winlogbeat-as-a-docker-sibling-sidecar-container/217409>\
**Category:** Beats\
**Tags:** docker, windows, winlogbeat\
**Created:** [January 31, 2020, 3:10pm UTC](https://discuss.elastic.co/t/winlogbeat-as-a-docker-sibling-sidecar-container/217409 "2020-01-31T15:10:48Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![zhammer](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zhammer/32/61858_2.png) [@zhammer](https://discuss.elastic.co/u/zhammer)\
**Post date:** [January 31, 2020, 3:10pm UTC](https://discuss.elastic.co/t/winlogbeat-as-a-docker-sibling-sidecar-container/217409/1 "2020-01-31T15:10:48Z")

</div>

i'd like to ship winlogbeat as a sibling/sidecar container to an app container to ship an app's event logs, rather than as a windows service running within the app container. this would fit well with a current setup where filebeat runs alongside an app container and reads/ships the app's logs from a shared `logs` volume.

i've set up a playground repo where i try to do this by mounting the app's event log directory to a shared volume and having winlogbeat read from those files, but since they're live `evtx` files, it seems that windows has an exclusive lock, restricting winlogbeat from reading them.

here's the playground: [https://github.com/zhammer/winlogbeat-sidecar](https://github.com/zhammer/winlogbeat-sidecar)

(this may _not_ be possible, but would love to hear from folks who've attempted to set this up)

---

<div class="post-metadata">

**Author:** ![zhammer](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zhammer/32/61858_2.png) [@zhammer](https://discuss.elastic.co/u/zhammer)\
**Post date:** [January 31, 2020, 3:11pm UTC](https://discuss.elastic.co/t/winlogbeat-as-a-docker-sibling-sidecar-container/217409/2 "2020-01-31T15:11:28Z")

</div>

here's the readme from the playground for easy view:

# winlogbeat-sidecar

playground for trying to get a `winlogbeat` sidecar job to read event logs from an `app` container as a `filebeat` sidecar would read text logs.

current approach is to mount the app's `C:\Windows\System32\winevt\Logs` to a shared volume and have `winlogbeat` read from those `.evtx` files, but it seems that those files have a restrictive lock:

```auto
{"level":"warn","timestamp":"2020-01-30T17:24:18.342Z","caller":"beater/eventlogger.go:113","message":"EventLog[c:\\alloc\\data\\Application.evtx] Open() error. No events will be read from this source. failed to get handle to event log file c:\\alloc\\data\\Application.evtx: The process cannot access the file because it is being used by another process."}
{"level":"warn","timestamp":"2020-01-30T17:24:18.344Z","caller":"beater/eventlogger.go:113","message":"EventLog[c:\\alloc\\data\\System.evtx] Open() error. No events will be read from this source. failed to get handle to event log file c:\\alloc\\data\\System.evtx: The process cannot access the file because it is being used by another process."}
{"level":"warn","timestamp":"2020-01-30T17:24:18.344Z","caller":"beater/eventlogger.go:113","message":"EventLog[c:\\alloc\\data\\Security.evtx] Open() error. No events will be read from this source. failed to get handle to event log file c:\\alloc\\data\\Security.evtx: The process cannot access the file because it is being used by another process."}

```

interested in any approaches to make this work (if it's possible)!

# setup

run: `docker-compose up`

containers:

- `app`: powershell script that logs both to a log file and an event log on a loop
- `winlogbeat`: winlogbeat container that tries to read from mounted `evtx` event log files from `app`, outputs to console
- `filebeat`: example filebeat container that successfully reads from mounted `.log` file from `app`, outputs to console

# notes

this follows an [example in the winlogbeat FAQs](https://www.elastic.co/guide/en/beats/winlogbeat/current/reading-from-evtx.html) for reading from `.evtx`, though in that case winlogbeat reads from archived `.evtx` files, hence no lock conflict

---

<div class="post-metadata">

**Author:** ![zhammer](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zhammer/32/61858_2.png) [@zhammer](https://discuss.elastic.co/u/zhammer)\
**Post date:** [January 31, 2020, 3:13pm UTC](https://discuss.elastic.co/t/winlogbeat-as-a-docker-sibling-sidecar-container/217409/3 "2020-01-31T15:13:57Z")

</div>

also for context this is different from [Using Winlogbeat with Docker-Compose under Linux](https://discuss.elastic.co/t/using-winlogbeat-with-docker-compose-under-linux/205105) as in this setup the whole stack is on windows

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [February 6, 2020, 4:00am UTC](https://discuss.elastic.co/t/winlogbeat-as-a-docker-sibling-sidecar-container/217409/4 "2020-02-06T04:00:27Z")

</div>

To read from live event logs Winlogbeat uses the Windows Event Log API to communicate directly to the event log subsystem as opposed to using the filesystem to read from the evtx file.

So if an app is writing to the hosts event log using the Windows API then perhaps you can configure Winlogbeat without going straight to the evtx file. Like use `Get-WinEvent -ListLog *` to get the event log name and then setup Winlogbeat to read that channel.

I'm assume this wouldn't work at all with Hyper-V isolation mode for the container, but perhaps it works in process isolation mode.

---

<div class="post-metadata">

**Author:** ![zhammer](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zhammer/32/61858_2.png) [@zhammer](https://discuss.elastic.co/u/zhammer)\
**Post date:** [February 6, 2020, 4:33am UTC](https://discuss.elastic.co/t/winlogbeat-as-a-docker-sibling-sidecar-container/217409/5 "2020-02-06T04:33:06Z")

</div>

Ah got it. I’m going to do some research on using the event log api to read event logs from a remote host: [https://docs.microsoft.com/en-us/windows/win32/wes/accessing-remote-computers](https://docs.microsoft.com/en-us/windows/win32/wes/accessing-remote-computers).

---

<div class="post-metadata">

**Author:** ![zhammer](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zhammer/32/61858_2.png) [@zhammer](https://discuss.elastic.co/u/zhammer)\
**Post date:** [February 6, 2020, 4:47am UTC](https://discuss.elastic.co/t/winlogbeat-as-a-docker-sibling-sidecar-container/217409/6 "2020-02-06T04:47:38Z")

</div>

This seems like a great resource on the topic: [https://techblog.bozho.net/remote-log-collection-on-windows/](https://techblog.bozho.net/remote-log-collection-on-windows/)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 5, 2020, 4:58am UTC](https://discuss.elastic.co/t/winlogbeat-as-a-docker-sibling-sidecar-container/217409/7 "2020-03-05T04:58:25Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
