Winlogbeat.event_logs adding level causes data to stop flowing into Elasticsearch


#1

When I add level to any name, Application, Security or System, to only get those level events, the connection from the server in question, Windows Server 2008, breaks. Removing the level, and the connection comes back.
config snip;
winlogbeat.event_logs:

  • name: Application
    ignore_older: 72h
  • name: Security
  • name: System
    This works fine.

This does not;
winlogbeat.event_logs:

  • name: Application
    level: error
    ignore_older: 72h
  • name: Security
    level: critical, error, warning
  • name: System
    level: error,warning

Confusion abounds.


#2

Has anyone had this problem?
Is it a rookie config error?