Hi Mark,
This is the latest log from Winlogbeat.
2021-08-17T23:52:47.628Z INFO instance/beat.go:660 Home path: [C:\Program Files\Winlogbeat] Config path: [C:\Program Files\Winlogbeat] Data path: [C:\Program Files\Winlogbeat\data] Logs path: [C:\Program Files\Winlogbeat\logs]
2021-08-17T23:52:47.632Z INFO instance/beat.go:668 Beat ID: b7dead8d-7ba2-48ab-b7c1-3893289c3310
2021-08-17T23:52:47.725Z INFO [beat] instance/beat.go:996 Beat info {"system_info": {"beat": {"path": {"config": "C:\\Program Files\\Winlogbeat", "data": "C:\\Program Files\\Winlogbeat\\data", "home": "C:\\Program Files\\Winlogbeat", "logs": "C:\\Program Files\\Winlogbeat\\logs"}, "type": "winlogbeat", "uuid": "b7dead8d-7ba2-48ab-b7c1-3893289c3310"}}}
2021-08-17T23:52:47.727Z INFO [beat] instance/beat.go:1005 Build info {"system_info": {"build": {"commit": "651a2ad1225f3d4420a22eba847de385b71f711d", "libbeat": "7.12.1", "time": "2021-04-20T21:18:27.000Z", "version": "7.12.1"}}}
2021-08-17T23:52:47.727Z INFO [beat] instance/beat.go:1008 Go runtime info {"system_info": {"go": {"os":"windows","arch":"amd64","max_procs":2,"version":"go1.15.9"}}}
2021-08-17T23:52:47.729Z INFO [add_cloud_metadata] add_cloud_metadata/add_cloud_metadata.go:105 add_cloud_metadata: hosting provider type detected as aws, metadata={"account":{"id":"accountid"},"availability_zone":"us-east-1c","image":{"id":"ami-0f93c815788872c5d"},"instance":{"id":"i-0a461d23fba9d38f7"},"machine":{"type":"m4.large"},"provider":"aws","region":"us-east-1"}
2021-08-17T23:52:47.734Z INFO [beat] instance/beat.go:1012 Host info {"system_info": {"host": {"architecture":"x86_64","boot_time":"2021-06-07T04:13:15.66Z","name":"EC2AMAZ-TJPFT03","ip":["fe80::dc43:ac65:a217:8bba/64","10.1.1.60/20","::1/128","127.0.0.1/8"],"kernel_version":"10.0.17763.1935 (WinBuild.160101.0800)","mac":["12:92:fe:dc:6d:df"],"os":{"type":"windows","family":"windows","platform":"windows","name":"Windows Server 2019 Datacenter","version":"10.0","major":10,"minor":0,"patch":0,"build":"17763.1935"},"timezone":"GMT","timezone_offset_sec":0,"id":"d8914117-0efc-45b2-a11c-9592746c174e"}}}
2021-08-17T23:52:47.735Z INFO [beat] instance/beat.go:1041 Process info {"system_info": {"process": {"cwd": "C:\\Program Files\\Winlogbeat", "exe": "C:\\Program Files\\Winlogbeat\\winlogbeat.exe", "name": "winlogbeat.exe", "pid": 11092, "ppid": 12828, "start_time": "2021-08-17T23:52:47.365Z"}}}
2021-08-17T23:52:47.735Z INFO instance/beat.go:304 Setup Beat: winlogbeat; Version: 7.12.1
2021-08-17T23:52:47.735Z INFO [index-management] idxmgmt/std.go:184 Set output.elasticsearch.index to 'winlogbeat-7.12.1' as ILM is enabled.
2021-08-17T23:52:47.735Z INFO eslegclient/connection.go:99 elasticsearch url: https://endpoint.us-east-1.es.amazonaws.com:443
2021-08-17T23:52:47.735Z INFO [publisher] pipeline/module.go:113 Beat name: EC2AMAZ-TJPFT03
2021-08-17T23:52:47.736Z INFO beater/winlogbeat.go:69 State will be read from and persisted to C:\Program Files\Winlogbeat\data\.winlogbeat.yml
2021-08-17T23:52:47.785Z WARN [cfgwarn] registered_domain/registered_domain.go:61 BETA: The registered_domain processor is beta.
2021-08-17T23:52:47.842Z WARN [cfgwarn] registered_domain/registered_domain.go:61 BETA: The registered_domain processor is beta.
2021-08-17T23:52:47.854Z INFO kibana/client.go:119 Kibana url: https://endpoint.us-east-1.es.amazonaws.com:443/_plugin/kibana
2021-08-17T23:52:48.086Z INFO kibana/client.go:119 Kibana url: https://endpoint.us-east-1.es.amazonaws.com:443/_plugin/kibana
2021-08-17T23:52:48.132Z ERROR instance/beat.go:971 Exiting: 1 error: error loading index pattern: returned 401 to import file: <nil>. Response: {"statusCode":401,"error":"Unauthorized","message":"Authentication required"}
Thanks and regards,
Juan