# WinlogBeat DNS analytical log capture

**URL:** https://discuss.elastic.co/t/winlogbeat-dns-analytical-log-capture/167644
**Category:** Beats
**Tags:** winlogbeat
**Created:** [February 8, 2019, 2:10pm UTC](https://discuss.elastic.co/t/winlogbeat-dns-analytical-log-capture/167644 "2019-02-08T14:10:11Z")
**Posts on this page:** 1
**Showing post:** 2

<div class="post-metadata">

### Author: ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)
#### Post date: [February 9, 2019, 2:05am UTC](https://discuss.elastic.co/t/winlogbeat-dns-analytical-log-capture/167644/2 "2019-02-09T02:05:43Z")

</div>

Analytic and Trace logs require a different API than what Winlogbeat uses.

> [@Trace Event Logs](https://discuss.elastic.co/t/trace-event-logs/75537/2):
>
> Have you see this: [https://www.elastic.co/guide/en/beats/winlogbeat/current/configuration-winlogbeat-options.html#configuration-winlogbeat-options-event\_logs-name](https://www.elastic.co/guide/en/beats/winlogbeat/current/configuration-winlogbeat-options.html#configuration-winlogbeat-options-event_logs-name) Winlogbeat can read the logs listed by Get-WinEvent -ListLog \*. Only Analytic and Debug logs are based on ETW and Winlogbeat cannot read those. Analytic and Debug logs are disabled and hidden by default in event viewer. There has been a request to add a feature in Beats for ETW. [https://github.com/elastic/beats/issues/2073](https://github.com/elastic/beats/issues/2073)

---

_[View the full topic](https://discuss.elastic.co/t/winlogbeat-dns-analytical-log-capture/167644)._
