# Winlogbeat can't ingest archived .evtx files

**URL:** <https://discuss.elastic.co/t/winlogbeat-cant-ingest-archived-evtx-files/179851>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [May 6, 2019, 10:29pm UTC](https://discuss.elastic.co/t/winlogbeat-cant-ingest-archived-evtx-files/179851 "2019-05-06T22:29:19Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![franco.federico](https://avatars.discourse-cdn.com/v4/letter/f/67e7ee/32.png) [@franco.federico](https://discuss.elastic.co/u/franco.federico)\
**Post date:** [May 7, 2019, 10:28am UTC](https://discuss.elastic.co/t/winlogbeat-cant-ingest-archived-evtx-files/179851/2 "2019-05-07T10:28:06Z")

</div>

I tried to use another file that I created locally on the server saving all security event in a file with event viewer, but I have the same problem.

I found a similar problem in this thread

> [@Upload and parse exported .evtx files to Elasticsearch](https://discuss.elastic.co/t/upload-and-parse-exported-evtx-files-to-elasticsearch/175014):
>
> I have a use case scenario where I have to manually upload and parse Windows logs to Elasticsearch by using exported .evtx files. Splunk handles this fine with the "oneshot" command and I was wondering if anyone in this forum found a similar solution with Winlogbeat or tools that is utilizing Winlogbeat? I know that the latest version of Kibana supports upload of log files, however there is a limit to the size of files that can be uploaded, which in my case is not sufficient. The best workroun…

Is it released this functionality?

Thank you in advance  
Franco

---

_[View the full topic](https://discuss.elastic.co/t/winlogbeat-cant-ingest-archived-evtx-files/179851)._
